Research

Credit reporting: who answers for the data, and what should change

Bureaus are responsible in law for the data they hold. The problem is that the duties are rarely enforced, and some gaps belong to nobody.

· 6 min read

General information, not legal or financial advice.

A common view is that credit bureaus answer for nothing they hold, because every record comes from a lender. That is not the law. A bureau has its own duties over the data it collects and sells. The fair criticism is a different one: those duties are real but rarely enforced, and the system leaves gaps that nobody is clearly responsible for.

Who is responsible for what

Under Part IIIA of the Privacy Act and the Credit Reporting Code, the lender creates the record and the bureau keeps and sells it. Each has duties (Privacy Act 1988; Privacy (Credit Reporting) Code 2025).

DutyBureauLender
Keep data accurate, up to date and completeReasonable steps, for what it collects and what it discloses (s 20N)Reasonable steps (s 21Q)
Police the other sideContracts requiring accurate data, independent audits of them, action on breaches (s 20N(3); Code para 23)Review its systems when a bureau finds an error (Code para 5)
Test the dataRegular testing, targeted testing after an error, fix what is found (Code para 5(9))Tell the bureau of an error as soon as practicable (Code para 5)
Correct on requestFree, within 30 days, consulting the lender (s 20T)The same (s 21V)
Correct unaskedWhen satisfied a record is wrong (s 20S)The same (s 21U)
Report publiclyYearly statistics and an audit report; an independent review every three years (Code paras 23, 24)None
Update after a payment or closure—No set time in law; the industry standard is monthly, “best endeavours”

So a bureau is responsible. The weakness is in enforcement. The accuracy and correction duties carry no penalty of their own; a breach must be pursued as a general interference with privacy. The 2024 independent review found a single regulatory action on credit reporting, a 2016 determination ([2016] AICmr 88) about steering people to paid reports, not about errors. It called it a conflict of interest for bureaus to audit the lenders who are their paying customers, and found that those audits are not published or followed up (Review of Australia’s Credit Reporting Framework, pp. 57, 59, 121).

Is the lender-first model good or bad?

For it. Only the lender knows whether a payment was made, an arrangement agreed or an account closed, so the primary duty sits with the party that holds the facts. A bureau that verified every record itself would need access to every lender’s systems, and the cost would come back as higher enquiry fees. And the bureau is the one party that sees across lenders, so it can catch what no single lender can.

Against it. Errors bounce between the two. AFCA told the review that lenders “often try to shift responsibility onto credit bureaus”, and fraud victims are sent to lenders they never dealt with. About three in four AFCA credit reporting complaints are against lenders, and 16 systemic issues in three years affected 270,000 people, several from records a bureau’s validation rejected (Review, pp. 42, 46).

AFCA credit reporting complaints2020–212021–222022–232023–24
Against lenders5,7056,0495,7636,097
Against bureaus980740442426
Total, with others7,8667,8047,2097,642

Our view: the model is sound in principle. The lender should own the facts. But the bureau should own the checks only it can run, and both should answer for failure in a way that costs them something. Australia has the first half and very little of the second.

When a lender stops updating

  • A lender exits or ceases to exist. The bureau still holds the data and still owes accuracy and correction duties, but there is no one left to consult. The review records consumers stuck where they no longer have a relationship with the lender.
  • A debt is sold. Seller and buyer must tell the bureau within 45 days (Code para 13). The review found defaults “reset” when a later buyer lists them again.
  • A default is paid. It stays for five years with a note that it was paid; how fast the note is added is left to general accuracy duties.
  • A default is listed late. Five years runs from when the bureau receives it, not from when the default happened (s 20W), so a late listing can outlast the debt’s enforceability (Review, p. 49).
  • A small lender never reports. Comprehensive reporting is mandatory only for the largest banks; for everyone else it is voluntary, so many files are thin or one-sided.

Nothing in law says how quickly a lender must update a bureau. That one gap explains much of the rest.

Concentration and foreign ownership

The largest bureau is owned by a US-listed group and is estimated to hold 70% to 90% of the market. In August 2024 the ACCC did not oppose a UK-listed group buying the third bureau, reasoning that two weak rivals combined might constrain the leader better than apart. That leaves two main bureaus and a small challenger, and no licence: there is no public list of who is a credit reporting body (Review, pp. 20, 54, 108).

Foreign ownership is not, in itself, the problem: the same two groups run two of the UK’s three largest agencies, under licence. Data must already be stored in Australia unless regulations allow otherwise (s 20Q(3)), and it may be disclosed only to entities with an Australian link (s 20F). The review found no known major breach at an Australian bureau. What matters more is concentration. Most lenders use one bureau; enquiries are reported to cost more here than overseas for less information; and an outage in 2024 disrupted lending widely (Review, pp. 37, 54). A market with one dominant supplier and no licence has a single point of failure and weak pressure to improve.

What should change

Ranked by what each would fix for its cost. Most follow the review’s 37 recommendations, to which we found no government response by 10 October 2026 (Treasury); overseas precedents from the UK FCA, the US Fair Credit Reporting Act, the National Bank of Belgium and the Reserve Bank of India.

ChangeWhat it fixesWhoPrecedent
1. A legal clock for lenders: update within 10 business days of a payment, closure or settlementStale and paid-but-unmarked recordsPrivacy Regulation; data standardBelgium: 2 to 8 working days
2. Penalties attached to the accuracy and correction duties, on both sidesDuties nobody is fined for missingParliamentUS: “maximum possible accuracy”
3. Automatic compensation for corrections past 30 days, paid by whoever caused the delayDelay costs the consumer, not the firmRegulation; AFCA rulesIndia: ₹100 a day past 30 days since April 2024; lenders have 21 of the 30
4. Specified bureau checks: duplicate defaults, defaults on closed accounts, a lender that stops reporting, with a “not updated since” flagErrors only the bureau can seeCode; OAICUK common data format
5. Retention from the date of default; a $300 thresholdReset and small-debt listingsParliament; regulationReview recs 14, 16
6. One corrections portal across bureaus; disputed data suspended during fraud checksBeing passed between partiesIndustry; regulationReview recs 4, 5
7. Licence bureaus; regulator-required audits in place of bureaus auditing their customersThe conflict of interest; no registerParliament; ASIC with OAICUK, India, Singapore
8. Large lenders report to every bureau; no exclusive deals; continuity plansConcentration and outage riskTreasury; ACCCUK proposal CP26/7

Two cautions. Statutory damages on the US model bring a flood of claims, much of it through credit repair firms, who already lodge 22% of AFCA credit reporting complaints; fixed, automatic compensation is the better tool (Review, p. 48). And a bureau pushed to delete whatever is disputed would erase valid records: over half of correction requests are refused, often rightly.

What a lender can do now

  • Send updates within days of a payment, closure or arrangement, not at month end.
  • Reconcile what you sent with what each bureau holds, every month, and investigate every rejected record.
  • Never list a default while a hardship request or dispute is open; record the date of default yourself.
  • Answer a bureau’s consultation within its five-business-day window (Code para 20).

Sources

  1. Privacy Act 1988, compilation No. 104 (4 June 2026): Part IIIA, ss 20F, 20N, 20Q, 20S, 20T, 20W, 21Q, 21U and 21V.
  2. Privacy (Credit Reporting) Code 2025 (F2025L00385): paras 5, 9, 13, 20, 23 and 24.
  3. Treasury, Review of Australia’s Credit Reporting Framework, final report (September 2024, released 28 November 2024), and the review’s status page.
  4. UK Financial Conduct Authority, Credit Information Market Study MS19/1 (final report 5 December 2023) and CP26/7 (February 2026).
  5. US 15 U.S.C. § 1681i (reinvestigation) and § 1681n (civil liability).
  6. Reserve Bank of India, Compensation for delayed updation or rectification of credit information (circular of 26 October 2023, in force six months later).
  7. National Bank of Belgium, Central Individual Credit Register.