1. What is the Consumer Data Right?
  2. The Privacy Act, Australian Privacy Principles, and CDR Privacy Safeguards
  3. Key privacy obligations for data holders
    1. Privacy Safeguard 1 — openness and transparency
    2. Privacy Safeguard 10 — notifying consumers of disclosure
    3. Privacy Safeguard 11 — quality of CDR data
    4. Privacy Safeguard 13 — correction of CDR data
    5. Direct marketing
  4. Where data holders most often go wrong
  5. Consequences of breach
  6. How Artificer Legal can assist data holders
  7. Key takeaways

The Consumer Data Right (CDR) is a federal regime that gives consumers control over the data businesses hold about them. If your business is a CDR data holder — most commonly in banking or energy — you are subject to a distinct set of privacy obligations that sit alongside, and in some places override, the ordinary Australian Privacy Principles (APPs). Getting these obligations right matters: both the Australian Competition and Consumer Commission (ACCC) and the Office of the Australian Information Commissioner (OAIC) actively enforce the regime, and penalties for breach are real.

This article explains what the CDR is, which privacy rules apply to data holders, what those rules require in practice, where businesses most often come unstuck, and when to get legal advice.

What is the Consumer Data Right?

The CDR is established by Part IVD of the Competition and Consumer Act 2010 (Cth) (CCA). It requires businesses in designated sectors that hold consumer data to share that data with accredited data recipients (ADRs) — but only when the relevant consumer has given consent. The purpose of data sharing is typically to allow the ADR to provide a product or service: for example, comparing the consumer's current energy plan against alternatives or automatically switching financial products.

The CDR currently operates in banking (open since July 2020) and energy (open since November 2022). Non-bank lending is being phased in from mid-2026. Telecommunications has been designated as a future sector but has not yet launched.

The ACCC administers the CDR Rules and accreditation process. The OAIC regulates the privacy dimensions of the regime. Both agencies can take enforcement action.

The Privacy Act, Australian Privacy Principles, and CDR Privacy Safeguards

Three overlapping sets of rules may apply to your data if you are a data holder.

The Privacy Act 1988 (Cth) and APPs. Under the Privacy Act 1988 (Cth), the 13 APPs apply to private-sector organisations with an annual turnover above $3 million. Smaller businesses are generally exempt — but not always. Accredited data recipients, health service providers, and certain other entities are covered regardless of size. If your business holds data solely as a data holder (not an ADR), the ordinary APPs continue to apply to any CDR data that also qualifies as personal information.

CDR Privacy Safeguards. The Privacy Safeguards are a separate set of privacy principles that apply specifically to data collected and shared under the CDR regime. They are set out in Part IVD of the CCA. There are 13 Privacy Safeguards in total; which ones apply to you depends on your role in the regime.

How the two sets of rules interact. Where CDR data is also personal information, the APPs continue to apply — with two important exceptions. APP 10 (quality of personal information) and APP 13 (correction of personal information) are replaced by Privacy Safeguard 11 (quality of CDR data) and Privacy Safeguard 13 (correction of CDR data) once a data holder is required or authorised to disclose the data under the CDR Rules. In addition, data holders must comply with Privacy Safeguard 1 (openness and transparency) and Privacy Safeguard 10 (notifying consumers of disclosure) as obligations specific to their role.

Key privacy obligations for data holders

Privacy Safeguard 1 — openness and transparency

Every data holder must adopt an open and transparent approach to how it manages CDR data. In practice, this means maintaining a CDR policy — a document that is separate from your ordinary APP privacy policy and that covers:

  • how you manage CDR data;
  • how consumers can access and correct the data you hold about them; and
  • how consumers can make a complaint, including where and when a complaint can be lodged, how you will acknowledge receipt, and what information the complainant must provide.

The CDR policy must be made freely available, including through your consumer dashboard (see below). The OAIC publishes a guide to developing a CDR policy that sets out what the document must contain.

Some data holders also prepare a separate CDR management plan — an internal document that sets measurable goals and procedures for meeting ongoing CDR obligations. This is optional, but useful for demonstrating a systematic approach to compliance if regulators come calling.

Privacy Safeguard 10 — notifying consumers of disclosure

When you disclose CDR data to an accredited data recipient, you must notify the consumer through your consumer dashboard. The consumer dashboard is an online portal you are required to operate. It serves two functions: it gives consumers visibility over who their data has been shared with and on what basis, and it allows ADRs to request that you release data.

Notification through the dashboard is not optional and cannot be substituted with an email or other communication.

Privacy Safeguard 11 — quality of CDR data

You must take reasonable steps to ensure that the CDR data you hold is accurate, up-to-date, and complete before you disclose it. If you discover that data you have already shared was incorrect, you must:

  • inform the affected consumer;
  • take reasonable steps to correct the data; and
  • provide the corrected data to any ADR that previously received the inaccurate version.

This obligation mirrors the spirit of APP 10 but is calibrated for the CDR context, where errors in shared data can have downstream consequences for the products and services a consumer receives from an ADR.

Privacy Safeguard 13 — correction of CDR data

Where a consumer requests a correction to their CDR data, you must respond to that request. You must take reasonable steps to correct the data and, if the data was shared with an ADR while it was incorrect, provide the corrected data to the ADR as well.

Direct marketing

Data holders must not use CDR data for direct marketing unless the consumer has expressly consented. CDR data is not yours to use as a commercial asset — it exists so that consumers can exercise their data rights, not so that you can pitch them products.

Where data holders most often go wrong

Based on the OAIC's published CDR assessments, a number of recurring compliance gaps appear across data holders:

  • Inadequate CDR policies. Policies that are generic, incomplete, or not updated to reflect current CDR obligations are a common finding. The CDR policy must be distinct from your APP privacy policy and must cover the specific matters required by the CDR Rules — a boilerplate privacy statement does not satisfy the obligation.

  • Dashboard gaps. Some data holders have implemented dashboards that do not display all required disclosures or are difficult for consumers to locate and use. The dashboard must be readily accessible and must reflect disclosures in real time.

  • Data quality processes. Organisations that lack systematic data quality checks before disclosure risk breaching Privacy Safeguard 11. If you are sharing data that is stale, inaccurate, or incomplete, you may be in breach even if the error is inadvertent.

  • Direct marketing using CDR data. Using CDR data to target consumers — even where the business holds a general marketing consent — is a common misunderstanding. The consent required for CDR direct marketing must be specific to that use.

Consequences of breach

Both the ACCC and the OAIC have enforcement powers under the CCA and the Privacy Act 1988 (Cth). Enforcement action can be initiated by the regulator on its own motion or following a consumer complaint.

Available enforcement tools include:

  • issuing infringement notices (which carry financial penalties without the need for court proceedings);
  • accepting court-enforceable undertakings;
  • seeking injunctions and other court orders; and
  • initiating civil penalty proceedings in the Federal Court.

Enforcement action has already occurred. In one publicly reported case, National Australia Bank paid $751,200 in penalties for alleged breaches of the CDR Rules. While larger institutions are currently the primary focus of CDR enforcement, the regime applies to all designated data holders, and the ACCC and OAIC have made clear that compliance expectations apply across the board.

CDR privacy compliance involves multiple layers of overlapping obligations, and the line between what the Privacy Safeguards require and what the APPs require is not always obvious. A lawyer experienced in CDR can help you:

  • Audit your current position — reviewing your CDR policy, consumer dashboard, data quality procedures, and consent practices against the current regulatory requirements;
  • Draft or update your CDR policy — ensuring it is complete, accessible, and clearly differentiated from your APP privacy policy;
  • Advise on data governance — structuring your internal data handling processes to satisfy both the Privacy Safeguards and the APPs where they apply concurrently; and
  • Respond to regulator inquiries — if the OAIC or ACCC contacts you about a potential breach, having legal representation from the outset is important.

At Artificer Legal, our team works with businesses across banking, energy, and other sectors on CDR compliance. We take a practical approach: understanding your existing systems and building compliance frameworks that work for your business, not just on paper.

Key takeaways

The CDR places real and specific obligations on data holders that go beyond ordinary privacy compliance. A few points worth keeping front of mind:

  • The Privacy Safeguards and the APPs operate concurrently for CDR data that is also personal information, with Privacy Safeguards 11 and 13 replacing APP 10 and APP 13 once you are required or authorised to disclose.
  • Privacy Safeguards 1 and 10 impose obligations specific to data holders — a CDR policy and dashboard notification of every disclosure.
  • Both the ACCC and OAIC can take enforcement action, including seeking civil penalties, and have already done so against large institutions.
  • The CDR is still expanding: if your sector is not yet designated, it may be soon, and building compliance infrastructure in advance is far easier than retrofitting it under regulatory pressure.

If you are unsure whether your business is a data holder, or whether your current practices meet the requirements, speaking with a lawyer familiar with the CDR regime is the clearest path forward.