Asia-Pacific Australia

Australia's Consumer Data Right: Open Banking and Beyond

The CDR regime: consumer-directed data sharing in banking, energy, and non-bank lending, accreditation, privacy safeguards, and how it interacts with the Privacy Act.

Regulation

Competition and Consumer Act 2010 Part IVD (Consumer Data Right, since 2019); CDR Rules

Max Penalty

Civil penalties aligned to the Privacy Act top tier: up to AUD 50M / 3x benefit / 30% adjusted turnover

Enforcing Authority

ACCC and OAIC jointly; Treasury sets policy

Official Source

www.oaic.gov.au

Executive Summary

  • The CDR lets consumers direct data holders to share their data with accredited recipients through standardized APIs: banking first (from July 2020), then energy (November 2022), with non-bank lending designated as the next sector.
  • Participation on the recipient side requires accreditation from the ACCC, with security, insurance, and governance conditions, or operation through sponsorship and representative models.
  • Thirteen CDR-specific privacy safeguards displace the APPs for CDR data, generally stricter, with express consent, purpose limits, deletion/de-identification duties, and marketing restrictions.
  • The OAIC handles CDR privacy complaints and breaches; the ACCC polices accreditation, conduct, and the rules; penalties align with the Privacy Act's top tier.
  • Reforms since 2024 have simplified consent flows and operational rules to lift usage, and 'action initiation' (payments and account switching by instruction) is legislated but awaiting activation.

The Consumer Data Right is Australia’s bet that portability works better as infrastructure than as a legal right. Rather than letting individuals request exports one at a time, the CDR obliges banks and energy retailers to expose standardized APIs, licenses who may receive the data, scripts the consent journey, and wraps the whole flow in a privacy regime stricter than the Privacy Act it sits beside. Uptake has lagged ambition, which is why the rules keep being simplified, but the architecture is now the regional reference point alongside Korea’s MyData.

RegimeCompetition and Consumer Act Part IVD + CDR Rules
Sectors liveBanking (2020), energy (2022); non-bank lending phasing in
RegulatorsACCC (conduct, accreditation) + OAIC (privacy)
Max penaltyAUD 50M / 3x benefit / 30% turnover tier

How the system works

Data holders (banks, energy retailers) must share designated data sets, account, transaction, product, and usage data, at the consumer’s direction, through APIs conforming to the Consumer Data Standards, free of charge, with consumer dashboards showing active authorizations.

Accredited data recipients collect only with express, granular, time-boxed consent, use data only for the consented purpose, and face deletion or de-identification duties when data becomes redundant. The direct-marketing prohibition is near-absolute, a deliberate inversion of the open-data fear that portability becomes a marketing pipeline.

The privacy safeguards replace the APPs for CDR data and travel with it. Breaches route to the OAIC under the NDB scheme’s machinery, and safeguard contraventions carry the same top-tier penalties as serious Privacy Act interferences.

Why compliance teams should care even outside banking

Three reasons. First, sector expansion is policy, not speculation: non-bank lenders are designated, and open finance is the stated trajectory, if you hold Australian consumer financial data, CDR obligations are a when-question. Second, the representative and trusted-adviser models pull fintechs, brokers, and advisers into the regime without full accreditation, often without their compliance teams noticing the safeguard switch-over. Third, the CDR’s consent UX rules, granular, dashboard-managed, expiry-bound, preview where Australian consent standards generally are heading under the Privacy Act reform agenda.

For the underlying general regime, see the Privacy Act reform guide and NDB scheme guide; to check what your Australian-facing surfaces collect today, run a free scan.

Frequently Asked Questions

How is the CDR different from GDPR data portability?

GDPR Article 20 gives a right to receive and transmit data with no infrastructure behind it. The CDR builds the infrastructure: mandatory machine-readable APIs to consumer data standards, an accreditation gate for recipients, defined data sets per sector, and its own privacy-safeguard regime with regulator supervision. Closest analogues are Korea's MyData and UK Open Banking, not GDPR.

Who can receive CDR data?

Accredited persons (unrestricted accreditation requires information-security capability audits and insurance), plus lighter routes: sponsored accreditation, the representative model (operating under an accredited principal), and trusted-adviser disclosures to professionals like accountants and brokers, added to reduce the accreditation barrier that suppressed early uptake.

What are the CDR privacy safeguards?

Thirteen statutory safeguards covering open management, anonymity options, consent-only collection, notification, use/disclosure limits, direct-marketing prohibition (stricter than APP 7), overseas disclosure conditions, accuracy, security, and correction, plus redundant-data deletion or de-identification duties. For CDR data they replace the corresponding APPs and are generally tougher.

Is consent under the CDR different from Privacy Act consent?

Yes, CDR consent is express, specific, time-limited (up to 12 months before re-authorization), granular per data set and use, and revocable through consumer dashboards both sides must provide. The 2024-2025 rule changes bundle related consents to cut friction, but the architecture stays consent-forward, no deemed or implied consent.

What sectors are covered now and next?

Banking (all major products since 2021-2022), energy (retail electricity and gas since November 2022), and non-bank lending (designated; data sharing obligations phasing in from 2025-2026). Telecommunications was assessed and deferred. 'Open finance' (superannuation, insurance) and action initiation are the stated direction of travel.

Regulatory Crosswalk

GDPR Art. 20Korea MyDataUK Open Banking

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.