Listen to the Brief

Too Busy to Read? We’ve Got You.

Get this blog post’s insights delivered in a quick audio format — all in under 10 minutes.

Download Audio

This audio version covers: One Bureau Told the Review Access Seeker Requests Rose About 500% in Five Years. The Privacy Act ‘Does Not Contemplate’ the Way Brokers Now Use It

CreditPolicy.ai: lender policy, servicing and client portals for Australian brokers
Compliance · At a glance

The Access Seeker channel, the reform package, and where it actually sits

The review says most Access Seekers are in practice licensed brokers and credit assistance providers — and that the Privacy Act never contemplated the channel being used this way. Here is the state of play as at October 2026.

The four numbers

~500% Growth in Access Seeker requests over the five years to 2023 Evidence from one credit bureau, cited in the review
37 Recommendations in the Richards review’s final report Final report dated 30 September 2024
5 yrs → 2 yrs Proposed enquiry retention period — removing about 60% of enquiry data over time Recommendation 13
$150 → $300 Proposed minimum default listing threshold Recommendation 16; current figure is s 6Q Privacy Act

How we got here

  • 30 August 2024 OAIC postpones the soft enquiries framework Consideration deferred pending release of the credit reporting framework review.
  • 30 September 2024 Richards review final report 37 recommendations, drawing on 31 written submissions. Recommendations 19 and 20 cover soft enquiries and the Access Seeker provision.
  • 24 March 2025 Privacy (Credit Reporting) Code 2025 made Made by Privacy Commissioner Carly Kind. It contains no soft enquiry framework.
  • May 2025 Policy functions transfer to Treasury Per Treasury’s own publication page for the review.
  • Early October 2026 Arca goes public with a reform package Still no published government response and no exposure draft.

The review’s own sequencing

Faster queue

Helps your clients’ files

  • Rec 16 — default threshold to $300 or higher. Regulation change only; no primary legislation needed.
  • Rec 13 — enquiry retention cut to two years. Minor drafting; flagged as able to move ahead of the main package.
  • Rec 14 — date-of-default field, retention running from the default date.
Slowest queue

Governs how you obtain files

  • Rec 19 — a statutory soft enquiry category that cannot be disclosed to third parties.
  • Rec 20 — Access Seekers to hold an ACL or be an authorised advisor; restrictions on disclosing the report onward.
  • Rec 17 — a minimum dollar threshold for reporting missed repayments.
The sentence to read twice. On brokers’ use of the channel, the review states: “The Privacy Act does not contemplate such extensive use of the Access Seeker channel.” On industry marketing, it states that some lenders or brokers advertise a ‘soft touch’ enquiry “but there is currently no clear legal basis for a ‘soft enquiry’.”

What this means for your week

Nothing in the law has changed. The practical action is to know how your own process works: who signs the written access-seeker authority and how often, what wording your marketing uses about credit checks, and what leaves your file and goes to a lender. Those are licensee questions, and they are easier to answer now than after an exposure draft lands.

Compliance

One Bureau Told the Review Access Seeker Requests Rose About 500% in Five Years. The Privacy Act ‘Does Not Contemplate’ the Way Brokers Now Use It

Arca wants a credit reporting reform package legislated. Underneath the consumer headline sit two recommendations that would reshape the channel brokers use to look at a client’s credit file before anyone applies.

The Broker Times · 8 October 2026 · Approx. 10 min read

Key takeaways

  • The review says “most Access Seekers are in practice mortgage brokers, credit assistance services that are required to hold a credit licence, or non-profit advisors” — and that the Privacy Act “does not contemplate such extensive use” of the channel.
  • Recommendation 20 would restrict the channel to Australian Credit Licence holders and authorised advisors, which favours brokers, but would also restrict an access seeker from passing the report on to a credit provider.
  • There is still no legal category called a “soft enquiry” in Australia. The Privacy (Credit Reporting) Code 2025 does not create one.
  • The changes that would help clients’ files — a shorter enquiry retention period and a higher default threshold — sit in the review’s faster queues. The two covering brokers’ own access sit in its slowest.
  • Nothing in the law has changed yet. Treasury’s page for the review publishes no government response, two years after the final report.

In the first week of October, Arca — the Australian Retail Credit Association — went public with a package of credit reporting reforms it wants the federal government to legislate. The number it led with was a consumer one: more than one in four Australians have avoided applying for a financial product because they feared what it would do to their credit score.

That figure will get the coverage. The part that matters more to your business is sitting underneath it, in a report dated two years ago that most brokers have never opened.

Arca’s package draws on the Review of Australia’s Credit Reporting Framework, the independent review conducted by Heidi Richards. Her final report is dated 30 September 2024, drew on 31 written submissions, and makes 37 recommendations. Two of them go straight at the mechanism brokers use every day to look at a client’s credit file before anyone applies for anything — and one of them would change what you are allowed to do with that file once you have it.

What Arca is asking for

Arca’s stated asks of government are: more data on credit reports, including amounts owed and amounts repaid; a formal “soft enquiries” category so consumers can compare products without affecting their score; stronger identity-fraud protections; lifting the default listing threshold from $150 to at least $300; better correction processes; closing gaps in comprehensive credit reporting; tighter regulation of credit repair firms; and targeted amendments to the Privacy Act and the National Consumer Credit Protection Act to unlock the rest.

Read the research with a caveat. The consumer research behind the campaign was commissioned by CreditSmart, a consumer education platform Arca owns and manages. Arca reports that 41 per cent of Millennials, 37 per cent of Gen Z and 34 per cent of households earning under $100,000 have avoided applying for a product over credit score concerns. The release does not publish a sample size, fieldwork dates or survey method, so those figures are best treated as Arca’s own research rather than established market data.

Arca chief executive Elsa Markula framed it as a competition problem, saying that “when household budgets are already stretched, we should be removing barriers to competition, not creating them,” and that where consumer advocates and industry ask for the same changes, “government should treat that as a mandate to act.”

The channel brokers quietly built a process on

Here is where it gets specific to the broker channel.

When you pull a client’s credit file before lodging, you are almost certainly doing it as an Access Seeker. Section 6L of the Privacy Act 1988 defines an access seeker as the individual themselves, or a person who is assisting the individual to deal with a credit reporting body or credit provider and who is authorised, in writing, by the individual to make the request. The same section says an individual must not authorise a credit provider, mortgage insurer or trade insurer to act as their access seeker. A credit assistance provider is not a credit provider — which is precisely why the channel is open to brokers and closed to the lenders they submit to.

The review found the channel has been used far more heavily than anyone drafting it envisaged. It records that one credit bureau provided evidence that Access Seeker requests increased by around 500 per cent over the five years to 2023. The review attributes the growth to brokers and other third parties using the provision “to obtain full credit report information without affecting the client’s credit report,” assisting consumers “by facilitating comparison of likely credit offers without the information being visible to other credit providers.”

The review’s assessment of that practice, as brokers use it, is broadly positive. It says the model “seems to be well understood, widely used for home lending, and provides important benefits for consumers,” notes that brokers are licensed and subject to a best interests duty under Part 3-5A of the Credit Act, and reasons that because a broker assessment is usually followed by a formal lender enquiry anyway, “little informational value is lost in practice.”

The Privacy Act does not contemplate such extensive use of the Access Seeker channel. Review of Australia’s Credit Reporting Framework, final report, September 2024

The review also observes that access seekers are not themselves subject to the information-safeguarding obligations in the credit reporting provisions of the Privacy Act, and that while the Act requires written authorisation, it “does not specify when or how often this consent must be obtained.”

The phrase in your marketing that has no statutory basis

The review is blunt about an industry habit. Discussing why consumers are confused about enquiries, it notes that “some lenders or brokers advertise that they can do a ‘soft touch’ enquiry that does not affect a consumer’s credit file, but there is currently no clear legal basis for a ‘soft enquiry’.”

That is not an allegation of wrongdoing. The Access Seeker route genuinely does not create a visible enquiry, so a broker describing it that way is describing a real outcome. The problem is that no legal category called a soft enquiry exists, so the phrase means whatever the user decides it means — and the review flags that inconsistency as a driver of correction requests and complaints. Enquiry information was the largest category of correction requests to illion at 51.8 per cent and the second largest at Equifax at 31.3 per cent, on the bureaus’ own 2023 reporting.

A better line for the client conversation. On the mechanics, the review records bureau evidence that a single enquiry contributes a modest negative amount to a credit score, while a large number contributes significantly to the predictive power of scores. That is more useful than either “it won’t matter” or “never shop around.”

What Recommendation 20 would actually change

Recommendation 20 would amend the Privacy Act to require access seekers to hold an Australian Credit Licence or be the consumer’s professional advisor or advocate holding an authority, and to prohibit access seekers from disclosing a consumer’s credit reporting information to third parties without the consumer’s explicit consent.

The first limb is good news for the broker channel. The review reaches it precisely because “most Access Seekers are in practice mortgage brokers, credit assistance services that are required to hold a credit licence, or non-profit advisors holding an authority from the consumer such as financial counsellors.” Restricting the channel to licensees would push out unlicensed credit repair operators and monitoring services the review was more worried about.

The second limb is the one to read against your own process. The review says the change “would not prohibit credit assistance providers that are affiliated with credit providers from obtaining a customer’s credit report with their consent, but the credit assistance provider should not disclose that report to an affiliated or unaffiliated credit provider.” It allows reasonable exceptions, including “to pre-populate information on a credit application with the consumer’s explicit consent,” and says access seekers “should use the information only to assist and advise consumers as directed” and “demonstrate strong controls for information security.”

In plain terms: if your process involves obtaining the report as an access seeker and then passing it, or its contents, to a lender, that is the practice the recommendation is aimed at. Nothing in the law has changed yet. But it is worth knowing which parts of your workflow depend on it.

Recommendation 19, and why the industry is not united

Recommendation 19 would put categories of credit enquiry into the Privacy Act, including soft enquiries that cannot be disclosed to third parties, with detail left to the Privacy Regulation. The review’s view is that soft enquiries should carry less data than a full Access Seeker report, but enough “for a lender to provide a consumer with a reasonably accurate price and loan quotation.”

That trade-off is contested. FinTech Australia argued to the review that limiting the data and using soft enquiries to replace the Access Seeker framework “will have an adverse impact on the ability of smaller lenders and neobanks to compete with large credit providers,” because incumbents already hold their own data on existing customers. The ABA and Equifax supported a framework sufficient for pre-qualification and pre-filling.

For brokers, the practical question is whether a future soft enquiry would carry enough data to price a scenario properly. One that supports a baseline eligibility check but not a credible rate quote would be a step backwards from the Access Seeker channel today.

The two changes that would help your clients’ files

Two other recommendations matter for the files sitting in your pipeline.

Recommendation 13 would cut the retention period for enquiry information from five years to two. The review estimates this “could remove approximately 60 per cent of enquiry information from the credit reporting framework over time,” and would align enquiry retention with consumer credit liability and repayment information. For the client who was declined twice in 2024 and is still carrying those marks, that is material.

Recommendation 16 would lift the default listing threshold to $300 or higher. Today, section 6Q of the Privacy Act permits a consumer credit default to be reported where the borrower is at least 60 days overdue, has been given written notice requesting payment, recovery is not statute-barred, and the overdue amount is at least $150 — or a higher amount prescribed by the regulations. The review benchmarked $300 against the minimum amount below which an energy retailer cannot disconnect a customer, and noted a $300 floor would exclude smaller BNPL debts while leaving mortgage, motor vehicle and credit card reporting untouched.

Recommendation 17 would add a minimum dollar threshold for reporting missed repayments, which today has none. Recommendation 14 would add a date-of-default field and start the retention clock from the default date rather than the listing date. Recommendation 7 would clarify that financial hardship information should only be used to assess applications for credit.

Where this actually sits right now

Not far along, and that is the point of Arca’s campaign.

The soft enquiry framework was originally proposed as a change to the industry code rather than the Act. The OAIC postponed considering it on 30 August 2024, pending release of the review. The Privacy (Credit Reporting) Code 2025 was then made by Privacy Commissioner Carly Kind on 24 March 2025 — and it contains no soft enquiry framework at all. There is still no legal category of soft enquiry in Australia.

On the legislative side, Treasury’s page for the review lists it as ongoing, records that “the policy functions transferred to the Treasury in May 2025,” and publishes no government response. Two years after the final report, there is no exposure draft in public.

The review’s own sequencing is instructive, and it cuts against the broker channel. It places Recommendation 16, the default threshold, in the group that can be progressed immediately by amending the Privacy Regulation alone. It places Recommendation 13, the enquiry retention cut, in the group needing only minor legislative drafting that government “may wish to progress relatively quickly.” But it places Recommendations 19 and 20 — soft enquiries and the Access Seeker rules — in the group it describes as entailing significant legislative changes.

Read that in order, and the likely sequence is that the changes helping your clients’ files arrive first, while the changes governing how you obtain those files sit in the slowest queue.

One obligation that is already live

There is a disclosure requirement in force now that is easy to miss, because it does not technically land on you.

Section 21C(1) of the Privacy Act requires a credit provider, at or before collecting personal information it is likely to disclose to a credit reporting body, to notify the individual of certain matters. Section 4(3)(a) of the Privacy (Credit Reporting) Code 2025 spells out what those matters include where the likely disclosure is an information request: that the individual’s consent to the disclosure is not required; that a record of the request may be used and disclosed for assessing creditworthiness, including calculating a credit score or rating; and “in general terms, how the information request may affect a credit score or credit rating.”

That obligation sits on the credit provider, not the credit assistance provider. But in a broker-originated deal you are the person in the room when the information is collected. If a client later says nobody told them a lodgement would mark their file, the conversation they remember is the one they had with you. How that disclosure is handled in your process is a question for your licensee, not something to improvise.

What to review this week

  1. Your written authority. Section 6L requires written authorisation from the client, but the Act does not say when or how often. Check whether yours is per-application or open-ended, and what your licensee expects.
  2. Your marketing wording. Search your own website, email templates and social posts for “soft check”, “soft touch”, “no impact on your credit score” and similar. The outcome may be real; the term has no statutory definition. Have the wording signed off.
  3. What leaves your file. Map what happens to an access-seeker report after you receive it. If any part of it goes to a lender, note that Recommendation 20 would require the client’s explicit consent for pre-population and would otherwise restrict disclosure.
  4. The enquiry conversation. Decide who explains, and when, that a formal lodgement creates an enquiry that stays on file for five years under current rules — and record it in your file notes.
  5. Information security. The review notes access seekers are not bound by the Part IIIA safeguards and says they should demonstrate strong controls. Check where credit reports sit in your CRM and who can open them.
  6. What you tell clients about small defaults. A $150 default is still a default today. Do not tell a client a small listing will drop away because the threshold is moving to $300 — it has not moved.
  7. Hardship scenarios. If a client’s file carries a hardship arrangement, confirm with the lender how it is used in assessment rather than assuming.

What to watch next

Watch for a government response or exposure draft from Treasury; a Privacy Regulation amendment lifting the default threshold, which needs no primary legislation and is the quickest change available; a further CR Code variation revisiting soft enquiries; and any movement on enquiry retention. Each one changes the script you use with clients, and the first two could arrive without consultation aimed at brokers.

The bottom line

Whether Arca’s campaign succeeds is not in brokers’ hands. What is in brokers’ hands is the recognition that one of the channel’s most useful everyday habits — looking at a client’s credit file before anyone applies — rests on a provision the independent reviewer says the Privacy Act never contemplated being used this way, and that the recommendation covering it would restrict what brokers can do with the report afterwards. That is not a reason to stop. It is a reason to know exactly how your process works before someone else decides how it should.

Frequently asked

An Access Seeker request does not appear on the credit report as a credit provider’s information request, which is why the channel is used for pre-qualification. The review describes brokers using it “to obtain full credit report information without affecting the client’s credit report.” A formal lodgement by a lender is a different thing and does create an information request on the file. Confirm the specifics with your bureau and your licensee rather than relying on a general statement.

Not as a defined category. The review states there is “currently no clear legal basis for a ‘soft enquiry’”, and the Privacy (Credit Reporting) Code 2025 does not create one. Recommendation 19 would put categories of enquiry, including non-disclosed ones, into the Privacy Act. That has not happened.

No. Section 6Q of the Privacy Act sets the amount at $150, or a higher amount prescribed by the regulations, alongside the other conditions — at least 60 days overdue, written notice given, and recovery not statute-barred. Recommendation 16 proposes $300 or higher by regulation, which is why it is one of the faster changes available, but it has not been made.

No obligation has changed. The practical work is process hygiene: knowing how your written authority is obtained and refreshed, what your marketing claims about credit checks, what happens to the report after you receive it, and where it is stored. Those are questions for your licensee’s compliance team.

Both, on its face. Limiting the Access Seeker channel to Australian Credit Licence holders and authorised advisors would favour licensed brokers over unlicensed operators. Restricting an access seeker from disclosing the report to a credit provider, affiliated or not, would constrain workflows that pass the report onward. The review contemplates an exception for pre-populating an application with the consumer’s explicit consent.

Breaking news for modern brokers

Lender policy, regulator moves and the numbers behind them — twice a day, broker-first.

More at The Broker Times →
Sources read for this article:
  • Review of Australia’s Credit Reporting Framework, Final Report, September 2024 (Heidi Richards, Independent Reviewer) — Treasury
  • Privacy Act 1988 (Cth), ss 6L, 6Q, 21C
  • Privacy (Credit Reporting) Code 2025, made 24 March 2025 — OAIC
  • OAIC, “Update on application to vary the Credit Reporting Code”
  • Arca media release, “Reforms needed to empower consumers and address credit fears”, October 2026
  • The Adviser, “Credit fears fuel push to overhaul reporting rules”, 8 October 2026
Interactive · Broker self-check

Would your credit-file process survive Recommendation 20?

Seven questions drawn from the review and the current instruments. Tick the ones you can answer with a confident yes today. Nothing is submitted or stored — it runs entirely in your browser.

0 of 7 confirmed

Start ticking to see where you sit

This is a prompt list, not a compliance assessment. Any gap it surfaces is a question for your aggregator or licensee’s compliance team, not a finding about your business.

Based on the Review of Australia’s Credit Reporting Framework (Final Report, September 2024), the Privacy Act 1988 and the Privacy (Credit Reporting) Code 2025. General information only — not legal or compliance advice.

Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator’s compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC’s responsible lending guidelines.

CreditPolicy.ai: lender policy, servicing and client portals for Australian brokers