Guide

What is the Consumer Data Right?

Last updated: September 2026

Short answer: The Consumer Data Right (CDR) is an Australian law that gives you the right to have data a business holds about you sent to another business you choose. It covers banking and energy today, it is regulated by the ACCC and the OAIC, and only businesses that pass ACCC accreditation are allowed to receive your data.

The idea behind it

For most of banking's history, the data about your own financial life sat with your bank and stayed there. If you wanted a budgeting tool, a better loan, or a comparison, you either did the work manually or handed over your login details to somebody.

The Consumer Data Right changes the default. Treasury describes its purpose as letting consumers "get value from data that is collected about them through the provision of specific goods and services by consenting to that data being shared with trusted accredited third parties".

The ACCC frames it as "a world leading data sharing and portability initiative" that "allows consumers to safely share the data that businesses hold about them" so they can "compare between products and services to find offers that best match their needs".

The key shift is that the data is yours to direct. You are not asking your bank for a favour; you are exercising a legal right.

The law behind it

The CDR is not a voluntary industry scheme or a marketing badge. It is legislation, and it is worth knowing the chain:

  • The Treasury Laws Amendment (Consumer Data Right) Act 2019 created it, by inserting a new Part IVD into the Competition and Consumer Act 2010.
  • The Competition and Consumer (Consumer Data Right) Rules 2020 are the operating manual. They "define the elements for consent, outline the accreditation framework and elaborate on the privacy aspects of the scheme".
  • The Consumer Data Standards, developed by the Data Standards Body, set the technical detail — "the format and process for transferring data".

This matters practically. Because the obligations sit in legislation rather than in a company's terms of service, they are enforceable by regulators, and a business that breaks them faces consequences rather than an apology.

Who's who

Three roles explain almost everything about how the system works. The OAIC defines the first two precisely:

Role What it means
Data holder "A business that holds consumer data and must transfer the data to an accredited data recipient at the consumer's request." In banking, this is your bank.
Accredited data recipient "An accredited data recipient has been accredited by the Australian Competition and Consumer Commission (ACCC) to receive consumer data to provide a product or service."
You The consumer. You decide whether any transfer happens at all, what is included, and for how long.

The flow is deliberately narrow. In the OAIC's words: "The business which has the consumer's data transfers only the data requested to the business the consumer has chosen to engage with."

Note the word only. A business cannot request your full financial history because it would be convenient; it receives the data you approved, and nothing else.

Which sectors it covers

The CDR was designed to roll out sector by sector rather than all at once. There is an important distinction here that often gets blurred: a sector being designated is the legal step that brings it into the system, which is not the same as consumer data sharing being live.

Sector Status
Banking Live since 1 July 2020. All Australian banks must participate.
Energy Live since 15 November 2022, for retailers in the National Electricity Market with more than 10,000 customers.
Non-bank lending Commences 9 November 2026. Product data sharing began 13 July 2026.
Telecommunications Designated. Designation is the legal step that brings a sector in; it is a separate stage from live consumer data sharing.

Banking and energy each have their own designation instrument — the Consumer Data Right (Authorised Deposit-Taking Institutions) Designation 2019 and the Consumer Data Right (Energy Sector) Designation 2020. Each one "set[s] out the classes of information that are subject to the CDR as well as who holds this information".

CDR or open banking — which is it?

These two terms get used interchangeably, and it causes a lot of confusion.

The Consumer Data Right is the framework. Open banking is the banking part of it. The same law, the same regulators and the same privacy safeguards also cover energy, and further sectors have been designated.

So all open banking in Australia is CDR, but not all CDR is open banking. If an Australian app says it uses "open banking", it is saying it operates inside this framework — which also tells you it must be receiving your data through an accredited data recipient.

Who regulates it

Two regulators divide the work, which is a real strength of the system — accreditation and privacy enforcement do not sit with the same body.

  • The ACCC runs "a rigorous ACCC accreditation process", provides guidance on the rules and standards, supports testing and onboarding, and monitors compliance and enforcement.
  • The OAIC, Australia's privacy regulator, enforces the 13 CDR privacy safeguards and handles consumer complaints.

One detail worth knowing, in the ACCC's own words about the data flowing through the system: "We don't see, store, or share the consumer data." The regulator operates the framework; it is not a party to your data.

What the CDR actually gives you

Stripped of the legal language, the framework gives you four concrete things:

  • You choose who. You "decide which businesses can see and use your data", and only accredited businesses are eligible.
  • You choose what. You "specify what types of data you wish to transfer" rather than handing over everything.
  • You choose how long. Consent expires after a maximum of 12 months, and you pick the period when you connect.
  • You can stop it. You can "stop the transfer of data at any time", and ask for data to be deleted once it is no longer needed.

For how those protections work in practice — including why an accredited business never needs your banking password — see our guide on whether open banking is safe in Australia.

How MyPelican fits in

MyPelican accesses CDR data through Fiskil, an Accredited Data Recipient regulated by the ACCC, accreditation number ADRBNK000246. Because the register is public, you can confirm that independently rather than taking our word for it.

In the language above: your bank is the data holder, Fiskil is the accredited data recipient, and you are the consumer who decides whether any of it happens. We collect only the minimum data needed to run the service, store it in Australia, and never see or store your banking password.

The specifics are in our CDR Policy and Privacy Policy.

Common questions

What is the Consumer Data Right?

The Consumer Data Right (CDR) is an Australian law that gives you the right to have data a business holds about you transferred to another business you choose. It was created by the Treasury Laws Amendment (Consumer Data Right) Act 2019, which inserted Part IVD into the Competition and Consumer Act 2010. The ACCC describes it as a data sharing and portability initiative that allows consumers to safely share the data that businesses hold about them.

Is the Consumer Data Right the same as open banking?

Not quite. The Consumer Data Right is the overall framework, and open banking is the banking part of it. The CDR also covers energy, and further sectors have been designated. So all open banking in Australia is CDR, but not all CDR is open banking.

Which sectors does the CDR cover?

Banking has been live since 1 July 2020 and energy since 15 November 2022, covering retailers in the National Electricity Market with more than 10,000 customers. Non-bank lending commences on 9 November 2026, with product data sharing having begun on 13 July 2026. Telecommunications has been designated, which is the legal step that brings a sector into the system, but designation and live consumer data sharing are different stages.

Who regulates the Consumer Data Right?

Two regulators share the work. The ACCC accredits data recipients, provides guidance on the rules and standards, and monitors compliance and enforcement. The OAIC, Australia's privacy regulator, enforces the 13 CDR privacy safeguards and handles complaints. The ACCC states that it does not see, store, or share the consumer data itself.

What is a data holder and an accredited data recipient?

The OAIC defines a data holder as "a business that holds consumer data and must transfer the data to an accredited data recipient at the consumer's request" — typically your bank. An accredited data recipient "has been accredited by the Australian Competition and Consumer Commission (ACCC) to receive consumer data to provide a product or service". Only accredited data recipients can receive your data.

What rights does the CDR give me?

You decide which businesses can see and use your data, and you specify what types of data are transferred. Your consent expires after a maximum of 12 months, and you can stop the transfer of data at any time. You can also ask for your data to be deleted once it is no longer needed, and businesses must destroy or de-identify data they no longer need.

More resources

This guide is general information about the Consumer Data Right framework, not personal financial or legal advice. Regulatory details and rollout dates can change — the OAIC, ACCC and Treasury are the authoritative sources. Details were current at the time of writing.