Banking APIOpen Banking AU

CDR Consent Flows, Renewal, and Revocation Management

Manage the full CDR consent lifecycle including collection, amendment, renewal, and revocation. Fiskil's consent management API ensures compliant handling of consumer data sharing authorisations across all Australian banks.

Dodo logo
Nissan logo
Light logo
Red Zed logo
Wage Tap logo
BDO logo
Adyen logo
Alex bank logo
AGL logo
Brighte logo
Data Zoo logo
Alinta logo
Tango logo
Dodo logo
Nissan logo
Light logo
Red Zed logo
Wage Tap logo
BDO logo
Adyen logo
Alex bank logo
AGL logo
Brighte logo
Data Zoo logo
Alinta logo
Tango logo

The Challenge

CDR consent rules are detailed and prescriptive, and getting any stage of the consent lifecycle wrong can result in compliance breaches or data access failures.

The Solution

Fiskil provides a comprehensive consent management layer that handles collection, amendment, renewal, and revocation in full compliance with CDR Rules.

Capabilities

How Fiskil Helps

Compliant Consent Collection

Pre-built consent collection flows that present the required information to consumers as mandated by CDR Rules, including data clusters, purposes, duration, and third-party disclosures.

Consent Amendment and Renewal

API endpoints for amending consent scope (adding or removing data clusters) and renewing consents before expiry, with correct handling of the CDR Rules distinction between amendment and new consent.

Multi-Channel Revocation Handling

Process consent revocations from any source: your application, the data holder's consent dashboard, or the CDR consent dashboard. Webhook notifications ensure your system responds to revocations in real-time.

Consumer Consent Dashboard

Embeddable consent dashboard UI components that display current consent status, data sharing scope, expiry dates, and connected accounts, meeting CDR requirements for consumer transparency.

Implementation

How It Works

1

Define Consent Requirements

Specify the CDR data clusters your application needs, the purpose for data use, the desired consent duration (up to 12 months), and any third-party data sharing arrangements. Fiskil validates these against CDR Rules.

2

Implement Consent Collection Flow

Use Fiskil's consent SDK or API to present the compliant consent request to the consumer. The consumer reviews the data sharing details and is redirected to their bank for authorisation via the FAPI 2.0 flow.

3

Manage Active Consents

Monitor active consents through Fiskil's API. Set up amendment flows for scope changes, configure renewal reminders before expiry, and integrate the consumer consent dashboard into your application.

4

Handle Revocation and Data Deletion

Process consent revocations from all channels via Fiskil's webhooks. When a consent is revoked, Fiskil triggers your data deletion workflow and provides confirmation records for compliance evidence.

Ready to get started?

Get your API keys today and start building with Fiskil's Banking API.

FAQs

Under CDR Rules, a consumer consent can be granted for a maximum of 12 months. After expiry, you must obtain a new consent to continue accessing data. Fiskil provides proactive renewal flows to re-engage consumers before their consent expires.

When consent is revoked (through any channel), you must stop accessing the consumer's data immediately and delete (or de-identify) any CDR data that is no longer required for a permitted purpose. Fiskil's webhook notifies your application of revocations in real-time and can trigger automated data deletion workflows.

Yes. CDR Rules allow consent amendment to add or remove data clusters. Fiskil's API supports consent amendments through the PATCH endpoint, and the consumer re-authorises at their bank for scope additions. Scope reductions can be processed without bank re-authorisation.

Yes. CDR Rules require that you provide consumers with a way to view their active consents, see what data is being shared, and revoke consent at any time. Fiskil provides embeddable dashboard components or you can build a custom dashboard using the consent API.

A consumer may grant separate consents for accounts at different banks. Fiskil manages each consent independently, tracking status, scope, and expiry per data holder. The consent API lets you query all consents for a consumer in a single call.

Get started today

Talk to us about what you're building and we'll show you how we can help.

Loading Contact Form...
Fiskil logo

© Fiskil 2026. All rights reserved.

CDR Consent Flows, Renewal, and Revocation Management |...