How credit reporting activities interact with the prior authorisation requirement
One of the four categories of processing that requires prior authorisation under the Protection of Personal Information Act (POPIA) is the processing of information for the purposes of credit reporting. A responsible party must obtain authorisation from the Information Regulator before carrying out this type of processing.
Credit reporting involves the processing of personal information relating to a data subject’s payment history, lending activity and creditworthiness. This information is typically used to create credit reports that lenders and credit providers rely on when assessing whether to extend credit. Because of the significant impact such reports can have on individuals’ access to finance and other opportunities, the law requires advance scrutiny by the Regulator.
The requirement applies to credit bureaux registered with the National Credit Regulator and to any person who processes personal information for credit reporting purposes. The activities covered are wide-ranging and include:
The category also covers related activities such as assessing applications for credit or insurance (where relevant), tracing consumers in respect of credit agreements, investigating applications for debt review, and supporting transactions that depend on the value of a business’s debtors book.
Credit reporting draws on a broad range of personal information. Examples include details relating to home loans, vehicle finance, personal loans, credit cards, store cards, overdrafts, utility accounts, insurance premiums, student loans, rental agreements and other forms of credit or deferred payment. Both positive and negative payment information may be processed, subject to the applicable retention and accuracy rules.
Credit reports influence decisions that can materially affect a data subject’s financial position and opportunities. Inaccurate, incomplete or unfairly processed information can lead to the refusal of credit, higher costs of borrowing, or other adverse outcomes. By requiring prior authorisation, POPIA ensures that the Information Regulator has an opportunity to examine the lawfulness of the processing before it begins.
This is consistent with the broader accountability obligations in the Act. Responsible parties must process personal information lawfully, ensure that it is accurate and up to date where necessary, and implement appropriate safeguards. When the processing involves credit reporting, these obligations are subject to the additional procedural requirement of prior authorisation.
A well-prepared Personal Information Impact Assessment is critical when applying for prior authorisation in this category. The Regulator will investigate the lawfulness of the proposed processing. The assessment should therefore address the purpose of the credit reporting activity, the categories of personal information involved, the measures taken to ensure accuracy and relevance, the retention periods applied, the security safeguards in place, and the impact on data subjects. Applications that lack this level of analysis are more likely to face delay or rejection.
From a governance perspective, credit reporting sits squarely within the risk and accountability expectations associated with King V. Boards overseeing organisations that process credit information need assurance that legal requirements are being met and that higher-risk processing activities are subject to appropriate controls. Evidence of prior authorisation, supported by thorough impact assessments, contributes to that assurance.
Organisations involved in credit reporting — whether as registered credit bureaux or as entities that process personal information for credit-related purposes — must treat the prior authorisation requirement as a prerequisite rather than an afterthought. Processing without the required authorisation, or continuing to process before the Regulator has completed its investigation, constitutes an offence and can attract significant penalties.
Credit information is powerful. POPIA recognises this by subjecting its use for reporting purposes to advance regulatory oversight. Meeting that requirement effectively depends on early identification of relevant activities, careful assessment of privacy risks, and disciplined adherence to the authorisation process.