The Consumer Data Standards are the technical API specifications for Australia's Consumer Data Right (CDR), covering banking, energy, and telecommunications data sharing.
View Official Specification →The Consumer Data Standards are developed and maintained by the Data Standards Body (DSB), hosted by CSIRO's Data61, as part of Australia's Consumer Data Right (CDR) framework. The CDR is a world-first cross-sector data sharing framework established by the Treasury Laws Amendment (Consumer Data Right) Act 2019.
The standards define RESTful API specifications for product reference data, account data, transaction data, direct debits, scheduled payments, and payees across the banking sector. They have been extended to cover energy data (including National Electricity Market usage and distributed energy resources) and are being developed for telecommunications.
The security model is built on the CDR Information Security Profile, which extends OAuth 2.0 with Proof Key for Code Exchange (PKCE), mutual TLS, and pushed authorisation requests. The consent model is highly granular, allowing consumers to specify data clusters, purposes, and sharing duration.
Version 1.29.0 includes non-bank lending data standards, enhanced energy data, and action initiation capabilities. The standards are developed through an open consultation process with regular decision proposals and maintenance iterations published on GitHub.
1 country currently implements this standard.
The Consumer Data Standards are the technical API specifications for Australia's Consumer Data Right (CDR), developed and maintained by the Data Standards Body (DSB) hosted by CSIRO's Data61. They define how banking, energy and (in development) telecommunications data is shared.
The CDR began in banking and has been extended to energy, with telecommunications standards in development. It is a cross-sector framework established by the Treasury Laws Amendment (Consumer Data Right) Act 2019.
They use the CDR Information Security Profile, which extends OAuth 2.0 with Proof Key for Code Exchange (PKCE), mutual TLS, and pushed authorisation requests, alongside a granular consent model covering data clusters, purposes and sharing duration.
They are developed and maintained by the Data Standards Body (DSB), hosted by CSIRO's Data61, through an open consultation process with decision proposals published on GitHub.
Fiskil helps financial institutions, fintechs, and enterprises around the world deliver a successful open finance program.
Products
© Fiskil 2026. All rights reserved.