Try the OS

Hong Kong CDS readiness guide · Free data checklist

Credit Data Smart readiness for Hong Kong money lenders

The Financial Services and the Treasury Bureau’s 2026 consultation conclusions propose that the phase-two arrangements take effect on 1 June 2027. Lenders should map data fields, sources, quality, ownership and test submissions now rather than wait until implementation.

Core definitions

Put similar concepts in the right place

Each component solves a different problem. Complete lending operations depend on clear data and workflow hand-offs.

Put similar concepts in the right place
ItemWhat it does in practice
011 June 2027The proposed phase-two implementation date stated in the consultation conclusions; the first six months would be a trial period for data submission.
02Submission every 30 daysCovers data relating to unsecured personal lending applications and approved loans, including credit amount, outstanding amount and repayment records.
03HK$50 million thresholdThe conclusions propose that a money lender reaching this total unsecured personal-loan amount must join CDS to obtain borrowers’ credit information.
04Monthly income below HK$12,000The conclusions propose that unsecured personal lending involving this income group also triggers joining and using CDS, regardless of scale.

Background

What Credit Data Smart is, and what it will ask of you

Most CDS material available to lenders is either a press summary or an implementation timeline. This section is the part in between: what the system is, who it catches, what the data has to contain, and what can be done before any interface specification exists.

What CDS actually is

Credit Data Smart is the infrastructure behind Hong Kong’s move from a single consumer credit reference agency to a multiple-agency model. Rather than one company holding consumer credit data, several credit reference agencies operate against a shared framework, with the stated aims of competition, service quality and operational resilience.

For a money lender the practical consequence is narrower than the policy debate. Consumer credit data the business already holds becomes something it is expected to produce on a schedule, in a defined shape, and to stand behind when it is wrong.

Who it applies to

The Financial Services and the Treasury Bureau’s 2026 consultation conclusions draw two separate lines, and they catch different lenders.

Submitting data. Money lenders engaged in unsecured personal lending would submit relevant borrowers’ personal credit data every 30 days, with the first six months operating as a trial period for data submission.

Joining and enquiring. A lender would additionally be required to join CDS and use it when assessing applications if its total unsecured personal loans reach HK$50 million, or if its business involves borrowers with monthly income below HK$12,000 — regardless of scale.

A lender can therefore fall inside the submission requirement without being inside the joining requirement. Which line applies changes how much work is ahead, so it is worth establishing before anything else.

What the data has to contain

The conclusions describe application and approved-loan data for unsecured personal lending, including credit amount, outstanding amount and repayment records. That reads narrowly until someone tries to produce it from a real ledger.

A submission is only as good as the record behind it. In practice, for every covered loan, a lender needs the application as it was actually made — including declines and withdrawals, not only approvals; the approved terms as they stood at approval rather than after later restructuring; the outstanding balance on the reporting date, reconciled to the ledger; the full repayment history including reversals, refunds, adjustments and write-offs; a borrower identity stable enough to survive name variations, duplicate records and corrections; and a reason and a named owner for every correction made after the fact.

Most lenders find the gap here rather than at the interface. Duplicate customers, missing identity fields, balances that do not reconcile and statuses that contradict one another are ordinary in a book that has never been asked to report on itself.

How to prepare before a specification exists

Waiting for the interface specification spends the one genuinely scarce resource, which is time. The work that pays off is the work any specification would require.

Scope first: which products, which lending companies, which borrower segments are covered. Then write a data dictionary naming, for every field, its source system, its format and the person who owns it. Fix identity matching before anything else, because data attributed to the wrong borrower is worse than data not submitted at all. Then rehearse: export a test batch, have business, operations, technology and compliance review it together, and keep the evidence that the review happened.

The six steps below set that out in order.

The legal constraints to hold in mind

Three things sit alongside CDS, and none of them are optional.

These are proposals, not final rules. The requirements above come from consultation conclusions. Phase-two detail should be confirmed against the licence conditions attached to the lender’s own money lenders licence, the platform specifications once published, and the latest official guidance. No lender should build to a summary — including this one.

Consumer credit data is personal data. The Personal Data (Privacy) Ordinance applies throughout, and the lender is the data user. That governs the purpose for which the data was collected, whether submission falls inside that purpose or needs fresh notification, how long it is kept, how accurate it is kept, and how the lender answers a borrower asking to access or correct their record. Changing what is done with data already held is a privacy question before it is a technical one.

Responsibility does not transfer. Software can organise, validate and export the data. The lender remains responsible for its accuracy, for the submission itself, and for interpreting how the requirements apply to its own business.

This page is general information about published proposals, not legal advice. Lenders should take their own legal and compliance advice on how the requirements apply to their licence and their loan book.

Get a consultation

A working session on your data and your ledger, not on your licence — legal and compliance advice should come from your own advisers.

Workflow

Six steps from loan ledger to CDS-ready data

  1. 01

    Determine scope

    Map products, security type, borrower type, company and income segment to identify potentially covered records.

  2. 02

    Build a data dictionary

    Define source, format and owner for application, approval, credit limit, outstanding balance, repayment and status fields.

  3. 03

    Control identity matching

    Set rules for HKID, names, loan numbers, duplicate records and corrections to avoid attributing data to the wrong customer.

  4. 04

    Validate completeness and accuracy

    Check missing fields, invalid dates, balance differences, duplicate transactions, reversals and inconsistent statuses.

  5. 05

    Rehearse output and review

    Export test batches for joint validation by business, operations, technology and compliance teams.

  6. 06

    Create evidence and cadence

    Retain output versions, reviews, error fixes, submission evidence and a named 30-day operating calendar.

Printable worksheet

Free: 14-point CDS data-readiness checklist

Give this checklist to business, operations, IT, compliance and your existing system vendor for a joint review.

Interactive CDS assessment: get a score and five priority actions

Practical evaluation

The highest-value work does not depend on waiting for an interface specification

Improve data quality now

Duplicate customers, missing identity data, incorrect balances and inconsistent statuses will not disappear when a new interface arrives.

Assign responsibility now

Name who produces, reviews, approves and submits each batch—and who decides on resubmission after an error.

Retain reproducible evidence now

Each batch should trace back to source records, transformation rules, review results and correction versions.

Frequently asked questions

Quick answers

What is Credit Data Smart (CDS)?

CDS is the infrastructure supporting Hong Kong’s multiple consumer credit reference agency model, with objectives including greater competition, service quality and operational resilience in consumer credit reference services.

Must every licensed money lender join CDS?

The consultation conclusions distinguish the data-submission requirement from the requirement to join and enquire. Money lenders engaged in unsecured personal lending will submit relevant data; joining and using CDS is tied to the HK$50 million threshold or lending to borrowers with monthly income below HK$12,000. Confirm individual application against final licence conditions and the latest guidance.

Will Covenant Desk submit data on behalf of the lender?

Covenant Desk can help organise, validate and export CDS-ready data. The lender remains responsible for data accuracy, final submission and regulatory interpretation.

Primary sources

Official sources and editorial note

This guide reflects official material available on the review date. Requirements can change; each institution should check the latest licence conditions and obtain legal or compliance advice. This page is not legal advice. Read our editorial and corrections policy.

Next step

Turn loan data into verifiable, exportable operating records before 2027.

Try Covenant Desk to see how applications, approved terms, balances, repayments, data quality and CDS-ready exports connect.

Try our lending OSSee the product overview
Covenant Desk is lending operations software. It does not provide loans, issue credit reports or replace the lender’s final credit decision.