Short answer: Open banking in Australia runs on the Consumer Data Right (CDR), a framework written into law. Only businesses accredited by the ACCC can receive your banking data, they must follow 13 legally binding privacy safeguards, and — in the OAIC's own words — an accredited business should never ask for your personal password. You choose what is shared and for how long, and you can stop it at any time.
Open banking is the part of Australia's Consumer Data Right that covers banking. The CDR is a legislative framework established under Part IVD of the Competition and Consumer Act 2010, and it gives you the right to have your own banking data sent to a business you choose.
The important word is sent. Your bank transmits the data directly to the accredited business over a regulated connection. Nobody logs in as you, and nobody screen-reads your internet banking on your behalf.
Two regulators oversee it. The ACCC accredits the businesses that may receive data. The OAIC — the national privacy regulator — enforces the privacy safeguards and handles complaints.
No, and this is the single most important thing to understand.
Under the CDR, you approve the sharing inside your own bank's login screen. The business receiving the data never sees your banking password, never stores it, and never needs it. The OAIC states it plainly:
"An accredited business should never ask for your personal password."
This is a useful test you can apply to any money app. If it asks you to type your internet banking password into its own screen, that is not CDR open banking, whatever the marketing says.
These two approaches are often described in similar language, but they are structurally different.
| CDR open banking | Sharing your login | |
|---|---|---|
| Where you approve it | Your bank's own login screen | The app's screen |
| Who holds your password | Only you and your bank | The app, or its provider |
| Accreditation required | Yes — ACCC accredited | No |
| Legally binding privacy safeguards | 13, enforced by the OAIC | General privacy law only |
| You can see and revoke access | Yes — via CDR dashboards | Varies |
| Time limit on access | Maximum 12 months, chosen by you | Until you change your password |
Far fewer businesses than most people assume. To receive CDR banking data, a business must be accredited by the ACCC and listed on the public CDR Register, each entry carrying an accreditation number and a current status.
The register is small. At the time of writing it listed 38 accredited data recipients in banking — not thousands. Accreditation is not a formality: businesses must meet strict requirements covering data collection, use and storage, and information security. If they fall short, the OAIC notes their accreditation can be suspended or cancelled, or they can be fined.
Because the register is public, you never have to take a company's word for it. If a business says it is accredited, you can look up its number and confirm the status yourself.
Accredited businesses are bound by 13 privacy safeguards. They are legal obligations, not voluntary commitments:
Two are worth dwelling on. Safeguard 7 restricts using your data for direct marketing. Safeguard 12 requires that data no longer needed is destroyed or de-identified — businesses cannot simply keep it indefinitely.
The CDR is opt-in, and the controls sit with you rather than the business:
There are two separate steps, which is why you see two dashboards: the consent you give the business receiving the data, and the authorisation you give your bank to release it. Either one can be withdrawn.
There is a defined complaints path, and it does not end with the company:
The OAIC describes its role as "an impartial third party who will try to resolve your complaint".
For transparency, here is how this applies to us specifically.
MyPelican accesses CDR data through Fiskil, an Accredited Data Recipient regulated by the ACCC, accreditation number ADRBNK000246. You can verify that number on the public CDR Register rather than taking our word for it.
The full detail is in our CDR Policy and Privacy Policy.
Open banking in Australia operates under the Consumer Data Right, a framework written into Part IVD of the Competition and Consumer Act 2010. Only businesses accredited by the ACCC may receive your banking data, they must comply with 13 legally binding privacy safeguards, and according to the OAIC an accredited business should never ask for your personal password. Accreditation can be suspended or cancelled, and businesses can be fined.
No. Under the Consumer Data Right you authorise the sharing inside your own bank's login screen, and the accredited business never sees or stores your banking password. The OAIC states plainly that an accredited business should never ask for your personal password. If any app asks you to type your banking password into its own screen, that is not CDR open banking.
You choose the period when you connect, up to a maximum of 12 months. CDR rules require that consent is voluntary and made as an active choice, and that it cannot be the result of default settings or pre-selected options. When the period ends, the business cannot collect new data unless you consent again.
Yes, at any time. You can withdraw consent from the accredited business's dashboard, and you can withdraw the authorisation you gave your bank from your bank's own CDR dashboard. You can also ask for your data to be deleted once it is no longer needed.
Accredited data recipients appear on the public CDR Register maintained by the ACCC, each with an accreditation number and a status. The register is small: at the time of writing it listed 38 accredited data recipients in banking. If a company claims accreditation, you can verify its number and status independently.
Complain to the business first. If it is not resolved, you can lodge a complaint with the Office of the Australian Information Commissioner using its CDR complaint form, or call 1300 363 992 (Monday to Thursday, 10am to 4pm AEST/AEDT). Individuals and small businesses with annual turnover of $3 million or less are eligible, and you have the right to appeal a decision.
This guide is general information about the Consumer Data Right framework, not personal financial or legal advice. Regulatory details can change — the OAIC and ACCC are the authoritative sources. Accreditation figures were current at the time of writing.