Australia Consumer Data Right - Banking (CDR)
The 13 CDR privacy safeguards (Competition and Consumer Act 2010 sections 56ED to 56EP) and the 11 information security obligations imposed by Schedule 2 of the CDR Rules 2020, being the 5 mandatory Steps and the 6 minimum control requirements. Broader operational obligations under the CDR Rules are tracked separately in the companion framework and are not claimed as complete here.
Australia Consumer Data Right - Banking (CDR) is a compliance framework from Australia with 2 domains and 24 controls that map to 28 other frameworks. The largest domains are Privacy Safeguards (13 controls), Information Security (Schedule 2) (11 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit legislation.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Information Security (Schedule 2)
The minimum information security controls for accredited data recipients (CDR Rules Schedule 2).
| Code | Title |
|---|---|
| AUCDR-IS-1 | Limit risk of unauthorised access to the CDR data environment |
| AUCDR-IS-2 | Secure the network and systems within the data environment |
| AUCDR-IS-3 | Securely manage information assets over their lifecycle |
| AUCDR-IS-4 | Formal vulnerability management program |
| AUCDR-IS-5 | Limit, prevent, detect and remove malware |
| AUCDR-IS-6 | Information security training and awareness program |
| AUCDR-IS-STEP1 | Step 1 - Define and implement security governance for CDR data |
| AUCDR-IS-STEP2 | Step 2 - Define the boundaries of the CDR data environment |
| AUCDR-IS-STEP3 | Step 3 - Have and maintain an information security capability |
| AUCDR-IS-STEP4 | Step 4 - Implement a formal controls assessment program |
| AUCDR-IS-STEP5 | Step 5 - Manage and report security incidents |
Privacy Safeguards
The 13 CDR Privacy Safeguards (Part IVD, Competition and Consumer Act 2010).
| Code | Title |
|---|---|
| AUCDR-PS-1 | Privacy Safeguard 1 - Open and transparent management of CDR data |
| AUCDR-PS-10 | Privacy Safeguard 10 - Notifying of the disclosure of CDR data |
| AUCDR-PS-11 | Privacy Safeguard 11 - Quality of CDR data |
| AUCDR-PS-12 | Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data |
| AUCDR-PS-13 | Privacy Safeguard 13 - Correction of CDR data |
| AUCDR-PS-2 | Privacy Safeguard 2 - Anonymity and pseudonymity |
| AUCDR-PS-3 | Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants |
| AUCDR-PS-4 | Privacy Safeguard 4 - Dealing with unsolicited CDR data |
| AUCDR-PS-5 | Privacy Safeguard 5 - Notifying of the collection of CDR data |
| AUCDR-PS-6 | Privacy Safeguard 6 - Use or disclosure of CDR data |
| AUCDR-PS-7 | Privacy Safeguard 7 - Use or disclosure of CDR data for direct marketing |
| AUCDR-PS-8 | Privacy Safeguard 8 - Overseas disclosure of CDR data |
| AUCDR-PS-9 | Privacy Safeguard 9 - Adoption or disclosure of government related identifiers |
Your Compliance Coverage
If you comply with Australia Consumer Data Right - Banking (CDR), you already cover:
GDPR
100%
24 controls mapped
Compare →APEC Cross-Border Privacy Rules (CBPR) System
96%
23 controls mapped
Compare →ISO 27701:2019
96%
23 controls mapped
Compare →+ 25 more: NIST SP 800-53 Rev 5 (88%), SOC 2 (83%)
See all 28 mapped frameworks ↓Maps to 28 other frameworks
What is Australia Consumer Data Right - Banking (CDR) and who does it apply to?
Australia Consumer Data Right - Banking (CDR) is a compliance framework from Australia with 2 domains and 24 controls. The 13 CDR privacy safeguards (Competition and Consumer Act 2010 sections 56ED to 56EP) and the 11 information security obligations imposed by Schedule 2 of the CDR Rules 2020, being the 5 mandatory Steps and the 6 minimum control requirements. Broader operational obligations under the CDR Rules are tracked separately in the companion framework and are not claimed as complete here. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Australia Consumer Data Right - Banking (CDR) actually require?
Australia Consumer Data Right - Banking (CDR) has 24 controls organised across 2 domains. The largest domains are Privacy Safeguards (13 controls), Information Security (Schedule 2) (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Australia Consumer Data Right - Banking (CDR) do I already cover?
Australia Consumer Data Right - Banking (CDR) maps to 28 other compliance frameworks. The top mapping partners are GDPR (100% coverage), APEC Cross-Border Privacy Rules (CBPR) System (96% coverage), ISO 27701:2019 (96% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Australia Consumer Data Right - Banking (CDR)?
Start your Australia Consumer Data Right - Banking (CDR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia Consumer Data Right - Banking (CDR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required