Back to Frameworks

Consumer Data Right (CDR) Framework (Australia)

Australia
vongoing (no fixed version)
4 domains
33 controls

Australia's Consumer Data Right (CDR) framework, established under Part IVD of the Competition and Consumer Act 2010, enables consumers to securely share their data with accredited third parties. It was first implemented for the banking sector (Open Banking) and subsequently rolled out for energy (July 2022) and non‑bank lending (2023). Additional sectors such as telecommunications and health are in advanced development. The framework is overseen by the ACCC and continuously updated through CDR rules and data standards.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

CDR: Accreditation

6 controls
Controls in the CDR: Accreditation domain of Consumer Data Right (CDR) Framework (Australia)6 controls
CodeTitle
CDR-ACC-1Unrestricted Accreditation
CDR-ACC-2Sponsored Accreditation
CDR-ACC-3Affiliate Accreditation
CDR-ACC-4CDR Representative Model
CDR-ACC-5Trusted Adviser and Insight Disclosure
CDR-ACC-6Accredited Action Initiator

CDR: Consent and Authorisation

6 controls
Controls in the CDR: Consent and Authorisation domain of Consumer Data Right (CDR) Framework (Australia)6 controls
CodeTitle
CDR-CON-1Voluntary Consent
CDR-CON-2Express Consent
CDR-CON-3Informed Consent
CDR-CON-4Specific Consent
CDR-CON-5Time-Limited Consent
CDR-CON-6Withdrawable Consent and Authorisation

CDR: Privacy Safeguards (CCA Part IVD Div 5)

13 controls
Controls in the CDR: Privacy Safeguards (CCA Part IVD Div 5) domain of Consumer Data Right (CDR) Framework (Australia)13 controls
CodeTitle
CDR-PS-1Privacy Safeguard 1: Open and Transparent Management of CDR Data
CDR-PS-10Privacy Safeguard 10: Notifying of the Disclosure of CDR Data
CDR-PS-11Privacy Safeguard 11: Quality of CDR Data
CDR-PS-12Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification
CDR-PS-13Privacy Safeguard 13: Correction of CDR Data
CDR-PS-2Privacy Safeguard 2: Anonymity and Pseudonymity
CDR-PS-3Privacy Safeguard 3: Seeking to Collect CDR Data from CDR Participants
CDR-PS-4Privacy Safeguard 4: Dealing with Unsolicited CDR Data
CDR-PS-5Privacy Safeguard 5: Notifying of the Collection of CDR Data
CDR-PS-6Privacy Safeguard 6: Use or Disclosure of CDR Data
CDR-PS-7Privacy Safeguard 7: Use or Disclosure of CDR Data for Direct Marketing
CDR-PS-8Privacy Safeguard 8: Overseas Disclosure of CDR Data
CDR-PS-9Privacy Safeguard 9: Adoption or Disclosure of Government Related Identifiers

CDR: Rules, Security and Oversight

8 controls
Controls in the CDR: Rules, Security and Oversight domain of Consumer Data Right (CDR) Framework (Australia)8 controls
CodeTitle
CDR-RULE-BREACHCDR Data Breach and Notifiable Data Breach
CDR-RULE-COMPLAINTSComplaints and Internal Dispute Resolution
CDR-RULE-CONFORMANCEConformance Testing (CTS)
CDR-RULE-DASHBOARDConsumer Dashboards and Receipts
CDR-RULE-DESIGNATIONSector Designation and Scope
CDR-RULE-OSPOutsourced Service Provider Arrangements
CDR-RULE-OVERSIGHTRegulator Oversight and Enforcement (ACCC and OAIC)
CDR-RULE-SECURITYInformation Security (CDR Rules Schedule 2)

Your Compliance Coverage

If you comply with Consumer Data Right (CDR) Framework (Australia), you already cover:

Maps to 3 other frameworks

33 total controls
GDPR
12 source controls mapped|5 target controls covered
36%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
3%
ISO 27001:2022
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is Consumer Data Right (CDR) Framework (Australia)?

Consumer Data Right (CDR) Framework (Australia) is a compliance framework from Australia with 4 domains and 33 controls. Australia's Consumer Data Right (CDR) framework, established under Part IVD of the Competition and Consumer Act 2010, enables consumers to securely share their data with accredited third parties. It was first implemented for the banking sector (Open Banking) and subsequently rolled out for energy (July 2022) and non‑bank lending (2023). Additional sectors such as telecommunications and health are in advanced development. The framework is overseen by the ACCC and continuously updated through CDR rules and data standards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Consumer Data Right (CDR) Framework (Australia) have?

Consumer Data Right (CDR) Framework (Australia) has 33 controls organised across 4 domains. The largest domains are CDR: Privacy Safeguards (CCA Part IVD Div 5) (13 controls), CDR: Rules, Security and Oversight (8 controls), CDR: Accreditation (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Consumer Data Right (CDR) Framework (Australia) map to?

Consumer Data Right (CDR) Framework (Australia) maps to 3 other compliance frameworks. The top mapping partners are GDPR (36% coverage), NIST SP 800-53 Rev 5 (3% coverage), ISO 27001:2022 (3% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Consumer Data Right (CDR) Framework (Australia) compliance?

Start your Consumer Data Right (CDR) Framework (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Consumer Data Right (CDR) Framework (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required