Banking APIOpen Banking AU

CDR Consent Flows, Renewal, and Revocation Management

Manage the full CDR consent lifecycle including collection, amendment, renewal, and revocation. Fiskil's consent management API ensures compliant handling of consumer data sharing authorisations across all Australian banks.

Dodo logo
Nissan logo
Light logo
Red Zed logo
Wage Tap logo
BDO logo
Adyen logo
Alex bank logo
AGL logo
Brighte logo
Data Zoo logo
Alinta logo
Tango logo
Dodo logo
Nissan logo
Light logo
Red Zed logo
Wage Tap logo
BDO logo
Adyen logo
Alex bank logo
AGL logo
Brighte logo
Data Zoo logo
Alinta logo
Tango logo

Consent management is the cornerstone of Australia's Consumer Data Right. Every data access request must be backed by an active, correctly scoped consumer consent. The CDR rules define strict requirements for how consent must be collected, displayed, amended, renewed, and revoked — and your application must handle each stage correctly. Fiskil's consent management API abstracts these requirements into a developer-friendly interface while ensuring full compliance with CDR Rules and Consumer Data Standards.

The Challenge

CDR consent rules are detailed and prescriptive, and getting any stage of the consent lifecycle wrong can result in compliance breaches or data access failures.

The Solution

Fiskil provides a comprehensive consent management layer that handles collection, amendment, renewal, and revocation in full compliance with CDR Rules.

Capabilities

How Fiskil Helps

Compliant Consent Collection

Pre-built consent collection flows that present the required information to consumers as mandated by CDR Rules, including data clusters, purposes, duration, and third-party disclosures.

Consent Amendment and Renewal

API endpoints for amending consent scope (adding or removing data clusters) and renewing consents before expiry, with correct handling of the CDR Rules distinction between amendment and new consent.

Multi-Channel Revocation Handling

Process consent revocations from any source: your application, the data holder's consent dashboard, or the CDR consent dashboard. Webhook notifications ensure your system responds to revocations in real-time.

Consumer Consent Dashboard

Embeddable consent dashboard UI components that display current consent status, data sharing scope, expiry dates, and connected accounts, meeting CDR requirements for consumer transparency.

Implementation

How It Works

1

Define Consent Requirements

Specify the CDR data clusters your application needs, the purpose for data use, the desired consent duration (up to 12 months), and any third-party data sharing arrangements. Fiskil validates these against CDR Rules.

2

Implement Consent Collection Flow

Use Fiskil's consent SDK or API to present the compliant consent request to the consumer. The consumer reviews the data sharing details and is redirected to their bank for authorisation via the FAPI 2.0 flow.

3

Manage Active Consents

Monitor active consents through Fiskil's API. Set up amendment flows for scope changes, configure renewal reminders before expiry, and integrate the consumer consent dashboard into your application.

4

Handle Revocation and Data Deletion

Process consent revocations from all channels via Fiskil's webhooks. When a consent is revoked, Fiskil triggers your data deletion workflow and provides confirmation records for compliance evidence.

In Practice

How Teams Use This

Wealth Platform Consent Renewal

A wealth management platform used Fiskil's proactive renewal notifications to prompt clients to re-authorise data sharing 14 days before consent expiry, maintaining continuous access to portfolio and banking data.

Achieved 89% consent renewal rate by proactively engaging clients before expiry, compared to 45% re-consent rate when reaching out after consent had already lapsed.

Lending App Consent Scope Management

A personal lending app initially collected consent for account and transaction data, then used consent amendment flows to add balance data access when they launched a new credit monitoring feature.

Amended existing consents rather than requiring new consent collection, resulting in 94% feature adoption rate as consumers only needed to approve the additional scope.

Insurance Comparison Handling Revocations

An insurance comparison site processed consent revocations from multiple channels (their app, bank dashboards, CDR dashboard) through Fiskil's unified webhook, triggering data deletion and confirmation.

Reduced revocation processing time from 48 hours (manual) to under 60 seconds (automated), with complete audit trails for every revocation and deletion event.

Technical Details

What You Integrate With

API endpoints

  • POST /v1/consents
  • GET /v1/consents/{consentId}
  • PATCH /v1/consents/{consentId}
  • DELETE /v1/consents/{consentId}
  • GET /v1/consents

Data returned

Consent records (scope, duration, status)

Consent amendment history

Revocation records and triggers

Data deletion confirmations

Consent analytics and metrics

Authorisation

OAuth 2.0 / FAPI 2.0 with PAR and JAR

Real-time data access.

Ready to get started?

Get your API keys today and start building with Fiskil's Banking API.

FAQs

Get started today

Talk to us about what you're building and we'll show you how we can help.

Fiskil logo

© Fiskil 2026. All rights reserved.