The Consumer Data Right is Australia’s bet that portability works better as infrastructure than as a legal right. Rather than letting individuals request exports one at a time, the CDR obliges banks and energy retailers to expose standardized APIs, licenses who may receive the data, scripts the consent journey, and wraps the whole flow in a privacy regime stricter than the Privacy Act it sits beside. Uptake has lagged ambition, which is why the rules keep being simplified, but the architecture is now the regional reference point alongside Korea’s MyData.
| Regime | Competition and Consumer Act Part IVD + CDR Rules |
|---|---|
| Sectors live | Banking (2020), energy (2022); non-bank lending phasing in |
| Regulators | ACCC (conduct, accreditation) + OAIC (privacy) |
| Max penalty | AUD 50M / 3x benefit / 30% turnover tier |
How the system works
Data holders (banks, energy retailers) must share designated data sets, account, transaction, product, and usage data, at the consumer’s direction, through APIs conforming to the Consumer Data Standards, free of charge, with consumer dashboards showing active authorizations.
Accredited data recipients collect only with express, granular, time-boxed consent, use data only for the consented purpose, and face deletion or de-identification duties when data becomes redundant. The direct-marketing prohibition is near-absolute, a deliberate inversion of the open-data fear that portability becomes a marketing pipeline.
The privacy safeguards replace the APPs for CDR data and travel with it. Breaches route to the OAIC under the NDB scheme’s machinery, and safeguard contraventions carry the same top-tier penalties as serious Privacy Act interferences.
Why compliance teams should care even outside banking
Three reasons. First, sector expansion is policy, not speculation: non-bank lenders are designated, and open finance is the stated trajectory, if you hold Australian consumer financial data, CDR obligations are a when-question. Second, the representative and trusted-adviser models pull fintechs, brokers, and advisers into the regime without full accreditation, often without their compliance teams noticing the safeguard switch-over. Third, the CDR’s consent UX rules, granular, dashboard-managed, expiry-bound, preview where Australian consent standards generally are heading under the Privacy Act reform agenda.
For the underlying general regime, see the Privacy Act reform guide and NDB scheme guide; to check what your Australian-facing surfaces collect today, run a free scan.