Back to Frameworks

Australia Consumer Data Right - Banking (CDR)

Australia
vPrivacy safeguards per Competition and Consumer Act 2010 Compilation No. 165; Schedule 2 security obligations per CDR Rules 2020 Compilation No. 10
2 domains
24 controls

The 13 CDR privacy safeguards (Competition and Consumer Act 2010 sections 56ED to 56EP) and the 11 information security obligations imposed by Schedule 2 of the CDR Rules 2020, being the 5 mandatory Steps and the 6 minimum control requirements. Broader operational obligations under the CDR Rules are tracked separately in the companion framework and are not claimed as complete here.

Verified

Australia Consumer Data Right - Banking (CDR) is a compliance framework from Australia with 2 domains and 24 controls that map to 28 other frameworks. The largest domains are Privacy Safeguards (13 controls), Information Security (Schedule 2) (11 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit legislation.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (2)

Information Security (Schedule 2)

11 controls

The minimum information security controls for accredited data recipients (CDR Rules Schedule 2).

Controls in the Information Security (Schedule 2) domain of Australia Consumer Data Right - Banking (CDR)11 controls
CodeTitle
AUCDR-IS-1Limit risk of unauthorised access to the CDR data environment
AUCDR-IS-2Secure the network and systems within the data environment
AUCDR-IS-3Securely manage information assets over their lifecycle
AUCDR-IS-4Formal vulnerability management program
AUCDR-IS-5Limit, prevent, detect and remove malware
AUCDR-IS-6Information security training and awareness program
AUCDR-IS-STEP1Step 1 - Define and implement security governance for CDR data
AUCDR-IS-STEP2Step 2 - Define the boundaries of the CDR data environment
AUCDR-IS-STEP3Step 3 - Have and maintain an information security capability
AUCDR-IS-STEP4Step 4 - Implement a formal controls assessment program
AUCDR-IS-STEP5Step 5 - Manage and report security incidents

Privacy Safeguards

13 controls

The 13 CDR Privacy Safeguards (Part IVD, Competition and Consumer Act 2010).

Controls in the Privacy Safeguards domain of Australia Consumer Data Right - Banking (CDR)13 controls
CodeTitle
AUCDR-PS-1Privacy Safeguard 1 - Open and transparent management of CDR data
AUCDR-PS-10Privacy Safeguard 10 - Notifying of the disclosure of CDR data
AUCDR-PS-11Privacy Safeguard 11 - Quality of CDR data
AUCDR-PS-12Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
AUCDR-PS-13Privacy Safeguard 13 - Correction of CDR data
AUCDR-PS-2Privacy Safeguard 2 - Anonymity and pseudonymity
AUCDR-PS-3Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
AUCDR-PS-4Privacy Safeguard 4 - Dealing with unsolicited CDR data
AUCDR-PS-5Privacy Safeguard 5 - Notifying of the collection of CDR data
AUCDR-PS-6Privacy Safeguard 6 - Use or disclosure of CDR data
AUCDR-PS-7Privacy Safeguard 7 - Use or disclosure of CDR data for direct marketing
AUCDR-PS-8Privacy Safeguard 8 - Overseas disclosure of CDR data
AUCDR-PS-9Privacy Safeguard 9 - Adoption or disclosure of government related identifiers

Your Compliance Coverage

If you comply with Australia Consumer Data Right - Banking (CDR), you already cover:

Maps to 28 other frameworks

24 total controls
GDPR
24 source controls mapped|25 target controls covered
100%
APEC Cross-Border Privacy Rules (CBPR) System
23 source controls mapped|45 target controls covered
96%
ISO 27701:2019
23 source controls mapped|59 target controls covered
96%
NIST SP 800-53 Rev 5
21 source controls mapped|64 target controls covered
88%
SOC 2
20 source controls mapped|47 target controls covered
83%
FedRAMP Moderate
18 source controls mapped|69 target controls covered
75%
FedRAMP High
18 source controls mapped|68 target controls covered
75%
NIST SP 800-53 Rev 5 MODERATE
17 source controls mapped|60 target controls covered
71%
NIST SP 800-53 Revision 5.1 HIGH
17 source controls mapped|61 target controls covered
71%
NIST SP 800-161 Rev 1
17 source controls mapped|42 target controls covered
71%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
16 source controls mapped|57 target controls covered
67%
NIST SP 800-53 Rev 5 LOW
15 source controls mapped|47 target controls covered
63%
ISO 27001:2022
15 source controls mapped|54 target controls covered
63%
ISO 27002:2022
15 source controls mapped|54 target controls covered
63%
NIST SP 800-171 Rev 3
13 source controls mapped|42 target controls covered
54%
HIPAA Security Rule
13 source controls mapped|36 target controls covered
54%
NIST SP 800-66 Rev 2
13 source controls mapped|34 target controls covered
54%
C5 (Germany)
13 source controls mapped|38 target controls covered
54%
NIST Cybersecurity Framework 2.0
13 source controls mapped|43 target controls covered
54%
Australian Privacy Principles (APPs)
13 source controls mapped|12 target controls covered
54%
AWS Well-Architected Security Pillar
12 source controls mapped|24 target controls covered
50%
PCI DSS 4.0
12 source controls mapped|34 target controls covered
50%
CMMC 2.0
12 source controls mapped|36 target controls covered
50%
Azure Security Benchmark
11 source controls mapped|37 target controls covered
46%
CIS Controls v8
10 source controls mapped|47 target controls covered
42%
Brazil Open Finance (Resolução Conjunta No. 1/2020)
4 source controls mapped|5 target controls covered
17%
ACSC Essential Eight
3 source controls mapped|5 target controls covered
13%
APRA CPS 234
1 source controls mapped|1 target controls covered
4%

What is Australia Consumer Data Right - Banking (CDR) and who does it apply to?

Australia Consumer Data Right - Banking (CDR) is a compliance framework from Australia with 2 domains and 24 controls. The 13 CDR privacy safeguards (Competition and Consumer Act 2010 sections 56ED to 56EP) and the 11 information security obligations imposed by Schedule 2 of the CDR Rules 2020, being the 5 mandatory Steps and the 6 minimum control requirements. Broader operational obligations under the CDR Rules are tracked separately in the companion framework and are not claimed as complete here. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Australia Consumer Data Right - Banking (CDR) actually require?

Australia Consumer Data Right - Banking (CDR) has 24 controls organised across 2 domains. The largest domains are Privacy Safeguards (13 controls), Information Security (Schedule 2) (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Australia Consumer Data Right - Banking (CDR) do I already cover?

Australia Consumer Data Right - Banking (CDR) maps to 28 other compliance frameworks. The top mapping partners are GDPR (100% coverage), APEC Cross-Border Privacy Rules (CBPR) System (96% coverage), ISO 27701:2019 (96% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Australia Consumer Data Right - Banking (CDR)?

Start your Australia Consumer Data Right - Banking (CDR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia Consumer Data Right - Banking (CDR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required