Short answer: The Consumer Data Right (CDR) is an Australian law that gives you the right to have data a business holds about you sent to another business you choose. It covers banking and energy today, it is regulated by the ACCC and the OAIC, and only businesses that pass ACCC accreditation are allowed to receive your data.
For most of banking's history, the data about your own financial life sat with your bank and stayed there. If you wanted a budgeting tool, a better loan, or a comparison, you either did the work manually or handed over your login details to somebody.
The Consumer Data Right changes the default. Treasury describes its purpose as letting consumers "get value from data that is collected about them through the provision of specific goods and services by consenting to that data being shared with trusted accredited third parties".
The ACCC frames it as "a world leading data sharing and portability initiative" that "allows consumers to safely share the data that businesses hold about them" so they can "compare between products and services to find offers that best match their needs".
The key shift is that the data is yours to direct. You are not asking your bank for a favour; you are exercising a legal right.
The CDR is not a voluntary industry scheme or a marketing badge. It is legislation, and it is worth knowing the chain:
This matters practically. Because the obligations sit in legislation rather than in a company's terms of service, they are enforceable by regulators, and a business that breaks them faces consequences rather than an apology.
Three roles explain almost everything about how the system works. The OAIC defines the first two precisely:
| Role | What it means |
|---|---|
| Data holder | "A business that holds consumer data and must transfer the data to an accredited data recipient at the consumer's request." In banking, this is your bank. |
| Accredited data recipient | "An accredited data recipient has been accredited by the Australian Competition and Consumer Commission (ACCC) to receive consumer data to provide a product or service." |
| You | The consumer. You decide whether any transfer happens at all, what is included, and for how long. |
The flow is deliberately narrow. In the OAIC's words: "The business which has the consumer's data transfers only the data requested to the business the consumer has chosen to engage with."
Note the word only. A business cannot request your full financial history because it would be convenient; it receives the data you approved, and nothing else.
The CDR was designed to roll out sector by sector rather than all at once. There is an important distinction here that often gets blurred: a sector being designated is the legal step that brings it into the system, which is not the same as consumer data sharing being live.
| Sector | Status |
|---|---|
| Banking | Live since 1 July 2020. All Australian banks must participate. |
| Energy | Live since 15 November 2022, for retailers in the National Electricity Market with more than 10,000 customers. |
| Non-bank lending | Commences 9 November 2026. Product data sharing began 13 July 2026. |
| Telecommunications | Designated. Designation is the legal step that brings a sector in; it is a separate stage from live consumer data sharing. |
Banking and energy each have their own designation instrument — the Consumer Data Right (Authorised Deposit-Taking Institutions) Designation 2019 and the Consumer Data Right (Energy Sector) Designation 2020. Each one "set[s] out the classes of information that are subject to the CDR as well as who holds this information".
These two terms get used interchangeably, and it causes a lot of confusion.
The Consumer Data Right is the framework. Open banking is the banking part of it. The same law, the same regulators and the same privacy safeguards also cover energy, and further sectors have been designated.
So all open banking in Australia is CDR, but not all CDR is open banking. If an Australian app says it uses "open banking", it is saying it operates inside this framework — which also tells you it must be receiving your data through an accredited data recipient.
Two regulators divide the work, which is a real strength of the system — accreditation and privacy enforcement do not sit with the same body.
One detail worth knowing, in the ACCC's own words about the data flowing through the system: "We don't see, store, or share the consumer data." The regulator operates the framework; it is not a party to your data.
Stripped of the legal language, the framework gives you four concrete things:
For how those protections work in practice — including why an accredited business never needs your banking password — see our guide on whether open banking is safe in Australia.
MyPelican accesses CDR data through Fiskil, an Accredited Data Recipient regulated by the ACCC, accreditation number ADRBNK000246. Because the register is public, you can confirm that independently rather than taking our word for it.
In the language above: your bank is the data holder, Fiskil is the accredited data recipient, and you are the consumer who decides whether any of it happens. We collect only the minimum data needed to run the service, store it in Australia, and never see or store your banking password.
The specifics are in our CDR Policy and Privacy Policy.
The Consumer Data Right (CDR) is an Australian law that gives you the right to have data a business holds about you transferred to another business you choose. It was created by the Treasury Laws Amendment (Consumer Data Right) Act 2019, which inserted Part IVD into the Competition and Consumer Act 2010. The ACCC describes it as a data sharing and portability initiative that allows consumers to safely share the data that businesses hold about them.
Not quite. The Consumer Data Right is the overall framework, and open banking is the banking part of it. The CDR also covers energy, and further sectors have been designated. So all open banking in Australia is CDR, but not all CDR is open banking.
Banking has been live since 1 July 2020 and energy since 15 November 2022, covering retailers in the National Electricity Market with more than 10,000 customers. Non-bank lending commences on 9 November 2026, with product data sharing having begun on 13 July 2026. Telecommunications has been designated, which is the legal step that brings a sector into the system, but designation and live consumer data sharing are different stages.
Two regulators share the work. The ACCC accredits data recipients, provides guidance on the rules and standards, and monitors compliance and enforcement. The OAIC, Australia's privacy regulator, enforces the 13 CDR privacy safeguards and handles complaints. The ACCC states that it does not see, store, or share the consumer data itself.
The OAIC defines a data holder as "a business that holds consumer data and must transfer the data to an accredited data recipient at the consumer's request" — typically your bank. An accredited data recipient "has been accredited by the Australian Competition and Consumer Commission (ACCC) to receive consumer data to provide a product or service". Only accredited data recipients can receive your data.
You decide which businesses can see and use your data, and you specify what types of data are transferred. Your consent expires after a maximum of 12 months, and you can stop the transfer of data at any time. You can also ask for your data to be deleted once it is no longer needed, and businesses must destroy or de-identify data they no longer need.
This guide is general information about the Consumer Data Right framework, not personal financial or legal advice. Regulatory details and rollout dates can change — the OAIC, ACCC and Treasury are the authoritative sources. Details were current at the time of writing.