Australia Consumer Data Right — Banking (CDR)
The Australian Consumer Data Right (CDR) for banking, mandated under the Competition and Consumer Act 2010 (amended by the Treasury Laws Amendment), gives consumers the right to share their banking data with accredited third parties. Administered by the ACCC (accreditation), OAIC (privacy), and Data Standards Body (technical standards). Effective July 2020, covering transaction accounts, credit cards, and lending products. Expanding to energy and telecommunications sectors.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Compliance and Enforcement
SEC compliance and enforcement actions
| Code | Title |
|---|---|
| BOSE-8 | Terms of Service Enforcement |
| BOSE-9 | Civil Penalties for Non-Reporting |
| CA-AODA-CE-01 | Accessibility Compliance Report |
| CA-AODA-CE-02 | Accessibility Policy and Plan |
| CA-AODA-CE-03 | Enforcement |
| CDR-13 | ACCC Enforcement |
| CDR-14 | OAIC Privacy Enforcement |
| DMA-ART11 | Compliance Reporting |
| DMA-ART13 | Anti-Circumvention |
| DMA-ART14 | Obligation to Inform About Concentrations |
| DMA-ART15 | Profiling Audit |
| DMA-ART8 | Compliance Measures |
| EAR-COMP-01 | Export Compliance Programme |
| EAR-COMP-02 | Screening Requirements |
| EAR-COMP-03 | Enforcement and Penalties |
| EU-EAA-CE-01 | Conformity Assessment |
| EU-EAA-CE-02 | Market Surveillance |
| EU-EAA-CE-03 | Consumer Complaints and Enforcement |
| EU-NIS2-EN-CE-01 | Supervisory Framework |
| EU-NIS2-EN-CE-02 | Supply Chain and SBOM |
| EU-NIS2-EN-CE-03 | Penalties |
| EUDR-CE-01 | Due Diligence Statements |
| EUDR-CE-02 | Country Benchmarking |
| EUDR-CE-03 | Penalties |
| HBNR-ENF-01 | Record-Keeping Requirements |
| HBNR-ENF-02 | FTC Enforcement Authority |
| HBNR-ENF-03 | State Attorney General Enforcement |
| NDB-DATA-BREACH-PLAN | Data breach response plan |
| NDB-S26WR | Commissioner-directed notification |
| PSTI-CMP-01 | Statement of Compliance |
| PSTI-CMP-02 | Importer and Distributor Obligations |
| PSTI-CMP-03 | Enforcement and Penalties |
| US-ITAR-EAR-CE-01 | Compliance Programme |
| US-ITAR-EAR-CE-02 | Violation Reporting |
| US-ITAR-EAR-CE-03 | Penalties |
| US-SEC-DA-CE-01 | Platform Compliance |
| US-SEC-DA-CE-02 | Custody and Reporting |
| US-SEC-DA-CE-03 | Enforcement Actions |
Consent and Authorization
| Code | Title |
|---|---|
| CDR-1 | Consumer Consent Framework |
| CDR-2 | Authorization Process |
| CDR-3 | Consent Withdrawal |
Data Classification — Banking
| Code | Title |
|---|---|
| CDR-7 | Consumer Information |
| CDR-8 | Product Use Information |
| CDR-9 | Product Information |
Data Holder Obligations
| Code | Title |
|---|---|
| CDR-4 | Machine-Readable Data Transfer |
| CDR-5 | Product Data Publication |
| CDR-6 | IT and Security Requirements |
Privacy and Security Safeguards
| Code | Title |
|---|---|
| CDR-10 | Privacy Safeguards |
| CDR-11 | Data Minimization |
| CDR-12 | Breach Notification |
Maps to 650 other frameworks
Frequently Asked Questions
What is Australia Consumer Data Right — Banking (CDR)?
Australia Consumer Data Right — Banking (CDR) is a compliance framework from Australia with 5 domains and 50 controls. The Australian Consumer Data Right (CDR) for banking, mandated under the Competition and Consumer Act 2010 (amended by the Treasury Laws Amendment), gives consumers the right to share their banking data with accredited third parties. Administered by the ACCC (accreditation), OAIC (privacy), and Data Standards Body (technical standards). Effective July 2020, covering transaction accounts, credit cards, and lending products. Expanding to energy and telecommunications sectors. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australia Consumer Data Right — Banking (CDR) have?
Australia Consumer Data Right — Banking (CDR) has 50 controls organised across 5 domains. The largest domains are Compliance and Enforcement (38 controls), Consent and Authorization (3 controls), Data Classification — Banking (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australia Consumer Data Right — Banking (CDR) map to?
Australia Consumer Data Right — Banking (CDR) maps to 650 other compliance frameworks. The top mapping partners are Notifiable Data Breaches Scheme (Australia) (36% coverage), EU Digital Markets Act (36% coverage), FTC Health Breach Notification Rule (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australia Consumer Data Right — Banking (CDR) compliance?
Start your Australia Consumer Data Right — Banking (CDR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia Consumer Data Right — Banking (CDR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required