1. What the Consumer Data Right is and the problem it solves
  2. Who is involved in the CDR
  3. How a data share happens step by step
  4. When obligations attach: designated sectors and thresholds
  5. The 13 privacy safeguards and what they require
  6. Where the scheme trips businesses up
  7. When to get professional help
  8. The consent trail is what gets tested

What the Consumer Data Right is and the problem it solves

The Consumer Data Right (CDR) is a national framework that gives consumers a legal right to access data that businesses hold about them, and to direct that the data be shared with trusted third parties. It is created by Part IVD of the Competition and Consumer Act 2010 (Cth) (the CCA), with the operating detail set out in the Competition and Consumer (Consumer Data Right) Rules 2020 (the CDR Rules) and in technical standards maintained by the Data Standards Body.

The scheme exists to solve a competition problem. Historically, your transaction history with a bank, or your usage data with an energy retailer, belonged in practice to the provider that held it. If you wanted a budgeting app to analyse your spending, or a lender to assess you on real data rather than a self-declared figure, there was no safe, standardised way to move the data. The CDR makes that possible: with the consumer's consent, a designated data holder must hand the data to an accredited recipient over secure, standardised interfaces. The result is meant to be more switching, sharper comparison, and products built on better data.

The right started with banking, generally known as open banking, and has since spread. For a small business the CDR matters in three ways. You may become a data holder if your sector is designated and you hold the relevant data. You may want to receive CDR data, which means accreditation or a formal arrangement with an accredited party. Or you may simply handle data and need to know where the CDR boundary sits relative to your existing privacy obligations. This guide explains who is involved, how a data share actually happens, when obligations attach, and where the traps are.

Who is involved in the CDR

The scheme is built around distinct roles, and each role carries different obligations. The ACCC sets out the practical division of labour:

  • CDR consumers: the individuals, and in some cases business consumers, whose data is in play. They decide what is shared, with whom, and for how long, and they can withdraw consent at any time.
  • Data holders: businesses in a designated sector that hold CDR data, such as banks and large energy retailers. They must respond to valid consumer requests and share the data through approved interfaces.
  • Accredited data recipients (ADRs): businesses the ACCC has accredited to receive CDR data. Accreditation comes in a few forms, including unrestricted, sponsored and streamlined accreditation, and carries conditions dealing with security, governance and reporting.
  • CDR representatives: businesses without their own accreditation that offer CDR-based services under a written arrangement with an accredited principal. The consumer deals with the representative, but under rule 1.10AA of the CDR Rules the accredited principal remains responsible for what the representative does.
  • Outsourced service providers: contractors that process CDR data for accredited participants. The accredited party stays on the hook for their conduct, which is why outsourcing arrangements need to mirror the rules.
  • The ACCC: accredits data recipients, operates the register, the accreditation application platform and the conformance test suite, monitors compliance, enforces the CDR Rules, and can grant exemptions from the regime.
  • The Office of the Australian Information Commissioner (OAIC): enforces the privacy safeguards, conducts assessments of how participants handle CDR data, and investigates complaints from consumers and small businesses.
  • Treasury and the Data Standards Body: Treasury is the policy agency and the Minister makes the rules; the Data Standards Body sets the technical and consumer-experience standards that make sharing interoperable.

How a data share happens step by step

The CDR only exists within sectors the Minister has designated by legislative instrument under section 56AC of the CCA. Within a designated sector, a share works like this:

  1. The consumer chooses a provider and consents: The consumer uses an app or service run by an accredited recipient (or its representative) and is taken through a consent flow. The consent must cover what data will be collected, from which data holder, for what purpose, and for how long. This is the engine of the whole scheme: nothing moves without a consent that is specific and informed.
  2. The data holder verifies and releases the data: On receiving a valid request, the data holder confirms the consumer's identity, typically through authentication such as a one-time password, and releases the agreed data over secure application programming interfaces built to the Consumer Data Standards. The transfer is logged and auditable, and the consumer is notified of the disclosure.
  3. The recipient uses the data only for the consented purpose: Privacy safeguard 6, in section 56EI of the CCA, limits how an accredited recipient may use or disclose CDR data. Privacy safeguard 7, in section 56EJ, goes further and prohibits using or disclosing CDR data for direct marketing unless the consumer has consented to that specific use. A new purpose means a new consent.
  4. The consumer can stop the share at any time: Consent can be withdrawn as easily as it was given, and the recipient must stop using the data. Privacy safeguard 12, in section 56EO, requires CDR data that is no longer needed to be destroyed or de-identified, subject to legal retention requirements.
  5. The consumer keeps visibility and rights: Consumers can see what has been shared and with whom, can ask for correction under privacy safeguard 13, and can complain to the OAIC if their data is mishandled.

When obligations attach: designated sectors and thresholds

Because designation drives everything, the practical question is which sectors are live and who is in scope. The current picture, based on the ACCC's rollout information and the CDR rollout pages, is:

  • Banking: all authorised deposit-taking institutions are in scope, and live sharing of consumer data began on 1 July 2020.
  • Energy: consumer data sharing began on 15 November 2022. Electricity retailers operating through the National Electricity Market with more than 10,000 small customers are required participants. Smaller retailers are not data holders unless they choose to participate voluntarily or become accredited. Product data sharing commenced earlier, on 1 October 2022.
  • Non-bank lenders: product data obligations commenced on 13 July 2026, with consumer data sharing to begin from 9 November 2026.
  • Telecommunications: the sector was designated in January 2022, but the rollout is paused while the Government works through a strategic assessment, so no live telco data sharing is happening yet.

Two things follow. First, the CDR is not economy-wide yet: consumers can only exercise the right within designated sectors, and businesses outside those sectors have no CDR data-holder obligations. Second, thresholds matter: a small energy retailer below the customer threshold is treated very differently from a large one, so the first step for any business is confirming whether it actually falls within a designation.

The 13 privacy safeguards and what they require

The 13 legally binding privacy safeguards sit in Division 5 of Part IVD of the CCA, in sections 56ED to 56EP. They apply to CDR data and work alongside, rather than replace, the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). In broad clusters:

  • Transparency and collection (safeguards 1 to 5): open and transparent management of CDR data, offering anonymity or pseudonymity where practical, collecting only through valid requests, destroying unsolicited data, and notifying consumers of collection.
  • Dealing with data (safeguards 6 to 10): the use and disclosure limits described above, the direct marketing ban, restrictions on disclosing CDR data overseas, limits on adopting government related identifiers, and notifying consumers when their data is disclosed.
  • Integrity (safeguards 11 to 13): keeping CDR data accurate and up to date, securing it against misuse and unauthorised access, destroying redundant data, and honouring correction requests.

The safeguards are civil penalty provisions. For a body corporate, the maximum penalty for a contravention is the greater of $10 million, three times the value of any benefit obtained, or 10% of adjusted turnover, under section 56EV of the CCA. The OAIC is the authorised applicant for penalties relating to the privacy safeguards and can conduct assessments of how participants handle CDR data. The ACCC enforces the CDR Rules themselves, which also designate many provisions as civil penalty provisions.

The Privacy Act 1988 continues to apply to personal information handled outside CDR flows, so most participants comply with both regimes at once. That includes the Notifiable Data Breaches scheme: a serious breach involving personal information must be assessed and, where it is an eligible data breach, notified to the OAIC and affected individuals. A CDR participant's security and incident response obligations therefore need to cover both the CDR-specific rules and general privacy law.

Where the scheme trips businesses up

The common failures in practice tend to cluster around consent and purpose:

  • Repurposing data without fresh consent: Using CDR data for marketing, profiling or a product the consumer never agreed to is the classic breach of privacy safeguard 7, and it is a civil penalty risk. Each new use needs its own consent.
  • Consent screens that are vague or bundled: The consent model only works if the consumer knows what they are agreeing to. Consent must be specific about the data, the purpose and the duration, and withdrawal has to be as simple as giving consent.
  • Outsourcing without flowing down the rules: A CDR representative or outsourced service provider that mishandles data is the accredited principal's problem. Written arrangements need to carry the same security, confidentiality, deletion and audit obligations the principal is under.
  • Forgetting deletion: Data that is no longer needed for the consented purpose must be destroyed or de-identified. Without a deletion routine, old data accumulates and becomes a liability in any assessment or investigation.
  • Treating a breach as an internal matter: Security incidents involving personal information can trigger the Notifiable Data Breaches scheme, with its own timeframes and notification duties. A tested response plan, rather than improvisation, is what keeps a breach from becoming an enforcement matter.
  • Assuming the CDR applies everywhere: Consumers have CDR rights only in designated sectors. Building a product on the assumption that you can demand a customer's data from any provider is a design error that no consent screen can fix.

When to get professional help

A lawyer is most useful early, at the design stage rather than after the fact. The points where advice typically pays for itself are:

  • Accreditation applications: Preparing the governance, security and consent documentation the ACCC expects, and understanding which form of accreditation fits your business model.
  • CDR representative and outsourcing arrangements: Drafting agreements that properly flow the CDR Rules and privacy safeguards down to representatives and service providers, including deletion and audit rights.
  • Consent journeys and public disclosures: Designing consent flows, dashboards and policies that match what the rules require, so that what you publish and what your systems do are consistent.
  • Responding to regulators: Handling OAIC complaints, ACCC compliance reviews or exemption applications, where the framing of the response matters as much as the underlying conduct.

A privacy lawyer can also map your data flows against both the CDR framework and the Privacy Act 1988, and flag where consumer law bites on what you tell customers about data use. That mapping is far cheaper before you build than after.

When the OAIC or the ACCC looks closely at a CDR participant, the first thing they weigh is whether each use of CDR data traces back to a consent that was specific, informed and current. The discipline that keeps a business safe is therefore a written one: for every category of CDR data you touch, record the purpose you told the consumer, the consent that supports it, how withdrawal works, and when the data must be deleted. If your sector is designated, or you are thinking about accreditation, doing that mapping before you build consent screens or sign outsourcing deals is the single highest-value step available, and a consultation with a lawyer to pressure-test it can be completed quickly and at modest cost.