{
  "service": "Creditcrest Privacy",
  "version": "1.0.0",
  "not_a_decision": "This is a record of dates and obligations under the Privacy Act 1988. It does not decide whether access should be refused, whether information is inaccurate, or whether a breach is likely to cause serious harm. Creditcrest Technologies is not a credit provider, is not a credit assistance provider, and does not hold an Australian credit licence. Its software produces evidence; the licensee makes the decision.",
  "stores": "nothing",
  "sources": {
    "app12_timing": {
      "cite": "Privacy Act 1988 Sch 1, APP 12.4",
      "quote": "The APP entity must: (a) respond to the request for access to the personal information: (i) if the entity is an agency—within 30 days after the request is made; or (ii) if the entity is an organisation—within a reasonable period after the request is made; and (b) give access to the information in the manner requested by the individual, if it is reasonable and practicable to do so."
    },
    "app12_guidance": {
      "cite": "OAIC, APP Guidelines ch 12, para 12.67",
      "quote": "APP 12.4(a)(ii) provides that an organisation must respond ‘within a reasonable period after the request is made’. … a reasonable period should not exceed 30 calendar days."
    },
    "app12_refusal": {
      "cite": "Privacy Act 1988 Sch 1, APP 12.9",
      "quote": "If the APP entity refuses to give access to the personal information because of subclause 12.2 or 12.3, or to give access in the manner requested by the individual, the entity must give the individual a written notice that sets out: (a) the reasons for the refusal except to the extent that, having regard to the grounds for the refusal, it would be unreasonable to do so; and (b) the mechanisms available to complain about the refusal; and (c) any other matter prescribed by the regulations."
    },
    "app13_timing": {
      "cite": "Privacy Act 1988 Sch 1, APP 13.5",
      "quote": "If a request is made under subclause 13.1 or 13.4, the APP entity: (a) must respond to the request: (i) if the entity is an agency—within 30 days after the request is made; or (ii) if the entity is an organisation—within a reasonable period after the request is made; and (b) must not charge the individual for the making of the request, for correcting the personal information or for associating the statement with the personal information (as the case may be)."
    },
    "s21t": {
      "cite": "Privacy Act 1988 s 21T(1), (3), (6) and (7)",
      "quote": "If a credit provider holds credit eligibility information about an individual, the provider must, on request by an access seeker in relation to the information, give the access seeker access to the information. … The credit provider must respond to the request within a reasonable period after the request is made. … If a credit provider is an organisation or small business operator, any charge by the provider for giving access to the information must not be excessive and must not apply to the making of the request. … If the provider refuses to give access to the information because of subsection (2), the provider must give the access seeker a written notice that: (a) sets out the reasons for the refusal …; and (b) states that, if the access seeker is not satisfied with the response to the request, the access seeker may: (i) access a recognised external dispute resolution scheme of which the provider is a member …"
    },
    "cr_code_access": {
      "cite": "Privacy (Credit Reporting) Code 2025 s 19(2) and 19(8)",
      "quote": "the body or provider must not provide access without first obtaining such evidence as is reasonable in the circumstances to satisfy itself of: (a) the identity of the person making the request; and (b) that person’s entitlement to access the information. … For the purposes of section 21T of the Act, a credit provider: … (b) should, unless unusual circumstances apply, provide access to the individual within 30 days of the request"
    },
    "s21v": {
      "cite": "Privacy Act 1988 s 21V(2) and (5)",
      "quote": "If the credit provider is satisfied that the personal information is inaccurate, out-of-date, incomplete, irrelevant or misleading, the provider must take such steps (if any) as are reasonable in the circumstances to correct the information within: (a) the period of 30 days that starts on the day on which the request is made; or (b) such longer period as the individual has agreed to in writing. … The credit provider must not charge the individual for the making of the request or for correcting the information."
    },
    "s21w": {
      "cite": "Privacy Act 1988 s 21W(2)",
      "quote": "If the credit provider corrects personal information about the individual under subsection 21V(2), the provider must, within a reasonable period: (a) give the individual written notice of the correction; and (b) if the provider consulted an interested party under subsection 21V(3) about the individual’s request—give the party written notice of the correction …"
    },
    "app11_2": {
      "cite": "Privacy Act 1988 Sch 1, APP 11.2",
      "quote": "If: (a) an APP entity holds personal information about an individual; and (b) the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule; and (c) the information is not contained in a Commonwealth record; and (d) the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information; the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified."
    },
    "s26wh": {
      "cite": "Privacy Act 1988 s 26WH(2)",
      "quote": "The entity must: (a) carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity; and (b) take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware as mentioned in paragraph (1)(a)."
    },
    "s26wk": {
      "cite": "Privacy Act 1988 s 26WK(2), as the OAIC states it",
      "quote": "Entities must prepare and give a copy of the statement to the Commissioner as soon as practicable after becoming aware of the eligible data breach"
    },
    "s26wl": {
      "cite": "Privacy Act 1988 s 26WL(3), as the OAIC states it",
      "quote": "Entities must notify individuals as soon as practicable after completing the statement prepared for notifying the Commissioner"
    },
    "app1_adm": {
      "cite": "Privacy Act 1988 Sch 1, APPs 1.7–1.9, as stated in the OAIC APP Guidelines ch 1 (not quoted from the compilation read, which predates their commencement)",
      "quote": "the kinds of personal information used in the operation of computer programs … the kinds of decisions made solely by the operation of computer programs … the kinds of decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs",
      "commences": "2026-12-10",
      "note": "OAIC APP Guidelines ch 1, footnote 1: APPs 1.7, 1.8 and 1.9 were introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and commence on 10 December 2026."
    }
  },
  "endpoints": {
    "POST /v1/privacy/access": "{request: {receivedOn, kind, identityCheckedOn?, respondedOn?, refused?}, asAt}",
    "POST /v1/privacy/correction": "{request: {receivedOn, kind, agreedInWritingUntil?, correctedOn?, noticeGivenOn?}, asAt}",
    "POST /v1/privacy/register": "{classes: [...]} — the register checked",
    "POST /v1/privacy/disposal": "{records, classes, asAt, legalHolds?} — what falls due",
    "POST /v1/privacy/breach": "{breach: {awareOn, assessedOn?, eligible?, ...}, asAt}",
    "POST /v1/privacy/automated-decisions": "{uses: [...], decisions: [{kind, solely}], asAt}"
  }
}