Compliance

Consumer Data Right (CDR) Compliance Guide

Updated February 1, 2026

12 min read

The Consumer Data Right (CDR) is Australia's open banking and open data framework, enabling consumers to share their data with accredited third parties. This comprehensive guide covers everything businesses need to know about CDR compliance, accreditation, and implementation.

What is the Consumer Data Right (CDR)?

The Consumer Data Right is an Australian government initiative that gives consumers greater control over their data. Launched in 2020 for banking and expanded to energy in 2022, CDR enables consumers to direct businesses to share their data with accredited third parties. This creates opportunities for innovation, competition, and better consumer outcomes across designated sectors.

CDR Access Models and Accreditation

To collect CDR data as a data recipient, a business must either be accredited by the Australian Competition and Consumer Commission (ACCC) or operate under an accredited person. There are two levels of accreditation — unrestricted and sponsored — and both apply across banking, non-bank lending and energy. Businesses that do not want to hold accreditation themselves can participate through a CDR representative arrangement with an accredited principal. CDR data sharing is read-only: it confers a right to receive data with the consumer's consent, not to initiate payments or write back to an account.

Unrestricted Accreditation

The full level of accreditation. It allows a business to collect, use and disclose CDR data for any purpose permitted under the CDR Rules. Applicants must provide an independent third-party assurance report demonstrating their information security capability, and must also have a privacy framework, external dispute resolution membership, adequate insurance, and the technical capability to meet the Consumer Data Standards.

Sponsored Accreditation

Sponsored accreditation removes the requirement for an independent third-party assurance report. Where a business has, or will have, an arrangement with an unrestricted accredited person acting as its sponsor, it may apply for accreditation and instead self-assess and attest that it satisfies the information security requirements. The sponsor takes on defined obligations in respect of its affiliate.

CDR Representative Arrangement

Not an accreditation level. A CDR representative is not accredited itself: it operates under a written arrangement with an accredited principal, and the principal remains responsible for compliance with the CDR Rules. This is the shortest route for a business that wants to use CDR data without holding accreditation. Fiskil acts as principal for CDR representatives.

Trusted Adviser Disclosure

Also not an accreditation level. A consumer may nominate a trusted adviser and consent to an accredited data recipient disclosing their CDR data to that adviser. The classes of trusted adviser are set out in the CDR Rules at subrule 1.10C(2) and include qualified accountants, admitted lawyers, registered tax agents and BAS agents, financial advisers and mortgage brokers.

Technical Standards and Security

CDR technical standards are based on international Financial-grade API (FAPI) security profile 2.0. Data holders (banks and energy retailers) must provide APIs that comply with Consumer Data Standards published by the Data Standards Body. Key technical requirements include: OAuth 2.0 with PKCE, mutual TLS authentication, JWT-secured authorization, and 128-bit AES encryption for data at rest.

CDR Data Cluster Coverage

Banking CDR covers accounts, transactions, balances, direct debits, scheduled payments, payees, and product information from all Australian Authorised Deposit-taking Institutions (ADIs). Energy CDR includes account details, billing history, usage data, meter information, and plan details from electricity and gas retailers. Additional sectors including telecommunications are planned for future rollout.

Consent Management Requirements

CDR consent must be explicit, informed, and time-limited. Consumers must authorize specific data clusters for specific purposes with defined expiry periods (maximum 12 months). Businesses must implement dashboards showing active consents, provide easy revocation mechanisms, and respect withdrawal of consent immediately. Consent cannot be bundled with terms and conditions for other services.

CDR Compliance Checklist

Achieve CDR compliance by following these steps: 1) Determine the appropriate access model for your business — unrestricted accreditation, sponsored accreditation, or a CDR representative arrangement with an accredited principal. 2) Engage legal counsel familiar with CDR Rules and Privacy Act. 3) Implement an information security program meeting the requirements in Schedule 2 of the CDR Rules. 4) Develop CDR privacy policy and consent management systems. 5) Build or integrate technical infrastructure meeting Consumer Data Standards. 6) Establish complaint and dispute resolution processes. 7) Obtain required insurance coverage. 8) Submit accreditation application with supporting evidence. 9) Undergo ACCC assessment process (typically 3-6 months). 10) Maintain ongoing compliance reporting and audits.

Frequently Asked Questions

Ready to Get Started?

Explore our APIs and start building secure, compliant financial data integrations today.

Fiskil logo

© Fiskil 2026. All rights reserved.