When asking for a consent, the accredited person must let the consumer actively select, or seek agreement to, the types of CDR data (collection and disclosure consents), the specific uses (use consents), the period (single occasion or a specified period) and the persons to whom data may be disclosed (disclosure consents); invite a business consumer statement where it deals with a CDR business consumer; seek express consent for each category; clearly separate data for which a fee will be charged or passed on and let the consumer choose on those items; and allow the redundant data deletion election. Direct marketing and de-identification consents must not use pre-selected options. It must give the consumer its name and accreditation number; how the collection, use or disclosure complies with the data minimisation principle (why collection is reasonably needed and for no longer than needed, and why use or disclosure goes no further than needed); for an insight consent, what the insight will reveal; any fee amount and the consequences of not consenting; for direct marketing, how data may be used or disclosed; for de-identification, the rule 4.15 information; where direct or indirect OSPs may receive or collect the data, that fact, each OSP's name, accreditation number if any, country if overseas, a link to the CDR policies, why the OSP needs the data and that more is in the policy; that consent can be withdrawn at any time; the rule 4.17 redundant data statement, the right to elect deletion and how; and, for an affiliate using a sponsor, the sponsor's details. Consent cannot be inferred or implied. The itemised OSP information applies from 12 November 2025, 12 months after the 2024 Measures No. 1 Rules commenced (rule 502).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.