Guide

Is open banking safe in Australia?

Last updated: September 2026

Short answer: Open banking in Australia runs on the Consumer Data Right (CDR), a framework written into law. Only businesses accredited by the ACCC can receive your banking data, they must follow 13 legally binding privacy safeguards, and — in the OAIC's own words — an accredited business should never ask for your personal password. You choose what is shared and for how long, and you can stop it at any time.

What open banking actually is

Open banking is the part of Australia's Consumer Data Right that covers banking. The CDR is a legislative framework established under Part IVD of the Competition and Consumer Act 2010, and it gives you the right to have your own banking data sent to a business you choose.

The important word is sent. Your bank transmits the data directly to the accredited business over a regulated connection. Nobody logs in as you, and nobody screen-reads your internet banking on your behalf.

Two regulators oversee it. The ACCC accredits the businesses that may receive data. The OAIC — the national privacy regulator — enforces the privacy safeguards and handles complaints.

Do I have to give an app my banking password?

No, and this is the single most important thing to understand.

Under the CDR, you approve the sharing inside your own bank's login screen. The business receiving the data never sees your banking password, never stores it, and never needs it. The OAIC states it plainly:

"An accredited business should never ask for your personal password."

This is a useful test you can apply to any money app. If it asks you to type your internet banking password into its own screen, that is not CDR open banking, whatever the marketing says.

CDR sharing vs handing over your login

These two approaches are often described in similar language, but they are structurally different.

CDR open banking Sharing your login
Where you approve it Your bank's own login screen The app's screen
Who holds your password Only you and your bank The app, or its provider
Accreditation required Yes — ACCC accredited No
Legally binding privacy safeguards 13, enforced by the OAIC General privacy law only
You can see and revoke access Yes — via CDR dashboards Varies
Time limit on access Maximum 12 months, chosen by you Until you change your password

Who is actually allowed to access your bank data

Far fewer businesses than most people assume. To receive CDR banking data, a business must be accredited by the ACCC and listed on the public CDR Register, each entry carrying an accreditation number and a current status.

The register is small. At the time of writing it listed 38 accredited data recipients in banking — not thousands. Accreditation is not a formality: businesses must meet strict requirements covering data collection, use and storage, and information security. If they fall short, the OAIC notes their accreditation can be suspended or cancelled, or they can be fined.

Because the register is public, you never have to take a company's word for it. If a business says it is accredited, you can look up its number and confirm the status yourself.

The 13 privacy safeguards

Accredited businesses are bound by 13 privacy safeguards. They are legal obligations, not voluntary commitments:

  • Open and transparent management of CDR data
  • Anonymity and pseudonymity
  • Seeking to collect CDR data from CDR participants
  • Dealing with unsolicited CDR data from CDR participants
  • Notifying of the collection of CDR data
  • Use or disclosure of CDR data
  • Use or disclosure of CDR data for direct marketing
  • Overseas disclosure of CDR data
  • Adoption or disclosure of government related identifiers
  • Notifying of disclosure of CDR data
  • Quality of CDR data
  • Security of CDR data, and destruction or de-identification of redundant CDR data
  • Correction of CDR data

Two are worth dwelling on. Safeguard 7 restricts using your data for direct marketing. Safeguard 12 requires that data no longer needed is destroyed or de-identified — businesses cannot simply keep it indefinitely.

What you control

The CDR is opt-in, and the controls sit with you rather than the business:

  • You choose the duration. You select the period your data is collected and used, up to a maximum of 12 months.
  • Consent must be a real choice. CDR rules require it to be voluntary and "made as an active choice", and it "cannot be the result of default settings or pre-selected options".
  • You can withdraw at any time. The accredited business must give you a dashboard to withdraw consent, and your bank must give you one to withdraw the authorisation you gave it.
  • You can require deletion. You can ask for your data to be deleted once it is no longer needed.

There are two separate steps, which is why you see two dashboards: the consent you give the business receiving the data, and the authorisation you give your bank to release it. Either one can be withdrawn.

If something goes wrong

There is a defined complaints path, and it does not end with the company:

  • Complain to the business first — the OAIC asks you to do this before escalating.
  • If it is not resolved, lodge a complaint with the OAIC at forms.oaic.gov.au/forms/complaint, or call 1300 363 992 (Monday to Thursday, 10am–4pm AEST/AEDT).
  • Individuals and small businesses with annual turnover of $3 million or less are eligible.
  • You have the right to appeal the OAIC's decision.

The OAIC describes its role as "an impartial third party who will try to resolve your complaint".

How MyPelican handles your data

For transparency, here is how this applies to us specifically.

MyPelican accesses CDR data through Fiskil, an Accredited Data Recipient regulated by the ACCC, accreditation number ADRBNK000246. You can verify that number on the public CDR Register rather than taking our word for it.

  • We never see or store your banking password.
  • We collect only the minimum data needed to run the service.
  • Your data is stored in Australia, encrypted with AES-256 at rest and TLS 1.3 in transit, with row-level security so only you can access your own data.
  • AI insights are generated from anonymised spending summaries processed inside Australian AWS infrastructure. No CDR data leaves Australia.
  • We do not sell your data and we do not use it for advertising.
  • Disconnect your bank and we delete your CDR data within 24 hours. Delete your account and everything goes within 30 days.

The full detail is in our CDR Policy and Privacy Policy.

Common questions

Is open banking safe in Australia?

Open banking in Australia operates under the Consumer Data Right, a framework written into Part IVD of the Competition and Consumer Act 2010. Only businesses accredited by the ACCC may receive your banking data, they must comply with 13 legally binding privacy safeguards, and according to the OAIC an accredited business should never ask for your personal password. Accreditation can be suspended or cancelled, and businesses can be fined.

Do I have to give an app my banking password?

No. Under the Consumer Data Right you authorise the sharing inside your own bank's login screen, and the accredited business never sees or stores your banking password. The OAIC states plainly that an accredited business should never ask for your personal password. If any app asks you to type your banking password into its own screen, that is not CDR open banking.

How long does open banking consent last?

You choose the period when you connect, up to a maximum of 12 months. CDR rules require that consent is voluntary and made as an active choice, and that it cannot be the result of default settings or pre-selected options. When the period ends, the business cannot collect new data unless you consent again.

Can I stop sharing my banking data?

Yes, at any time. You can withdraw consent from the accredited business's dashboard, and you can withdraw the authorisation you gave your bank from your bank's own CDR dashboard. You can also ask for your data to be deleted once it is no longer needed.

How do I check a company is accredited for open banking?

Accredited data recipients appear on the public CDR Register maintained by the ACCC, each with an accreditation number and a status. The register is small: at the time of writing it listed 38 accredited data recipients in banking. If a company claims accreditation, you can verify its number and status independently.

What can I do if something goes wrong with my CDR data?

Complain to the business first. If it is not resolved, you can lodge a complaint with the Office of the Australian Information Commissioner using its CDR complaint form, or call 1300 363 992 (Monday to Thursday, 10am to 4pm AEST/AEDT). Individuals and small businesses with annual turnover of $3 million or less are eligible, and you have the right to appeal a decision.

More resources

This guide is general information about the Consumer Data Right framework, not personal financial or legal advice. Regulatory details can change — the OAIC and ACCC are the authoritative sources. Accreditation figures were current at the time of writing.