Pillar · Consumer Data Right (CDR) Australia

CDR consent. Six requirements. Twelve-month max. Two-business-day withdrawal.

CDR consent is a strict subset of privacy consent — informed + voluntary + specific + current + time-bound + withdrawable. 12-month maximum duration. CDR Dashboard at every Data Holder + every Accredited Data Recipient gives customers one-click visibility + withdrawal. Below is each requirement + the practical implementation.

Why this lives on XIntelliSync, not on the OAIC CDR consent guidance

CDR consent is a strict subset of privacy consent — informed + voluntary + specific + current + time-bound + withdrawable. The CDR Dashboard at every Data Holder + every Accredited Data Recipient gives customers one-click visibility + withdrawal. XIntelliSync does not host the CDR Dashboard (that responsibility sits with the bank as Data Holder and our accredited partner as ADR), does not run the consent flow directly (the partner runs it), and does not retain data after the customer withdraws consent. What XIntelliSync DOES: receive the CDR feed downstream from our accredited partner, use it ONLY for the purposes covered by the customer's consent, and cease use within 2 business days of withdrawal. The article below is the six consent requirements + the 12-month maximum + the 2-business-day withdrawal honour.

← CDR pillar · See how XGVS works →

Six consent requirements

All six must be true. None can be skipped.

Informed

Clear plain-English explanation of what data is being shared, with whom, for what purpose, for how long. No jargon. No buried disclosures.

Voluntary

No bundled consent. No coercion (e.g. "agree or you cannot use the product"). Customer can decline without penalty. ADR must offer meaningful alternative.

Specific

Granular consent per data set + per use case. No "consent to everything" pattern. Customer ticks individual data sets + individual purposes.

Current

No rolling re-consent. No silent renewal. Consent is at the time of grant + relates to a specific point-in-time decision. Re-consent flow at expiry.

Time-bound

12-month maximum duration from grant. Customer can specify shorter (1 day to 12 months). At expiry, fresh consent flow required for renewal.

Withdrawable

One-click withdrawal at any time via the CDR Dashboard at the data holder OR the ADR. Withdrawal honoured within 2 business days. Records of consent + withdrawal retained.

All 22+ industries served

CDR consent context per industry.

Construction

Use case + consent context — Cash-flow visibility across project accounts via accredited finance brokers + accounting integrations.

Healthcare

Use case + consent context — Health sector designation under consideration in 2025-2026 Treasury review. My Health Record adjacent.

Hospitality

Use case + consent context — Multi-venue cash-flow consolidation + supplier-payment optimisation via accredited finance partners.

Retail

Use case + consent context — Settlement-account reconciliation + payment-provider data flows via banking sector + future merchant data.

Professional Services / Consulting

Use case + consent context — Practice cash-flow + invoice-financing decisions via accredited fintech partners.

Digital / Tech / SaaS

Use case + consent context — Many fintech SaaS apply for Accredited Data Recipient (ADR) status to consume CDR banking + energy data on behalf of customers.

Finance / Mortgage Brokers

Use case + consent context — Mortgage brokers + non-bank lenders + BNPL providers use CDR banking data for serviceability assessment + credit decisions.

Legal

Use case + consent context — Trust-account reconciliation + matter-cost forecasting via accredited accounting integrations.

Childcare / Early Learning

Use case + consent context — CCS + family payment reconciliation + parent-payment visibility via accounting partners.

Education / RTOs

Use case + consent context — Student-fee reconciliation + scholarship + grant payment tracking.

Manufacturing

Use case + consent context — Supplier-payment + customer-receivables cash-flow consolidation via accounting + ERP integrations using banking data.

Transport / Logistics

Use case + consent context — Fuel-card + customer-payment reconciliation + driver-payment tracking via banking data.

Mining / Resources

Use case + consent context — Royalty-payment + government-receivable reconciliation. Energy data critical for energy-intensive sites.

Agriculture / Primary Production

Use case + consent context — Farm-management-deposit (FMD) + grain/livestock-buyer payment + government-grant reconciliation.

Fitness / Health Clubs

Use case + consent context — Member DD payment + franchise-royalty payment reconciliation via banking sector data.

Not-for-Profit

Use case + consent context — Donation reconciliation + grant-payment tracking + ACNC reporting via accounting partners using banking data.

Events / Conferences

Use case + consent context — Ticketing-platform + sponsor-payment + supplier-payment reconciliation via banking sector data.

Creative / Photography / Production

Use case + consent context — Client-deposit + Screen Australia funding + royalty-payment tracking via banking sector data.

Marketing / Advertising Agencies

Use case + consent context — Client-retainer + media-buying account reconciliation via banking sector data.

HR / Recruitment

Use case + consent context — Placement-fee + payroll-on-charge reconciliation + invoice-finance use via banking sector data.

Insurance Brokers / Underwriters

Use case + consent context — Insurance brokers + underwriters increasingly use CDR for premium-finance + underwriting + risk assessment. Insurance sector designation under Treasury review 2025-2026.

Real Estate / Property Management

Use case + consent context — Trust-account + tenant-bond + commission reconciliation via banking sector data.

FAQs

CDR consent management — answered.

What is the CDR Dashboard?

The CDR Dashboard is the consumer-facing visibility + control surface required of every Data Holder + every Accredited Data Recipient. Customers can see: every active consent (which ADR, which data, which purpose, when granted, when expiring), full consent history, and one-click withdrawal control. Data Holder dashboard typically integrated into online banking + energy account portals; ADR dashboard typically integrated into the ADR product UI.

Can consent be longer than 12 months?

No. 12 months is the maximum consent duration under CDR Rules. At expiry: fresh consent flow required (no rolling re-consent). The 12-month maximum applies even where a customer wants longer-duration access — re-consent at 12 months is mandatory. ADRs build consent-renewal flows into their product to minimise churn at the 12-month mark.

How fast must withdrawal be honoured?

Within 2 business days from withdrawal action. Within that window: ADR ceases new data requests, deletes or de-identifies received data per CDR rules + retention requirements, updates the CDR Dashboard, notifies the data holder of withdrawal so the data holder can update their dashboard. Failure to honour within 2 business days is a CDR Rules breach reportable to ACCC + OAIC.

How does CDR consent differ from Privacy Act consent?

CDR consent is a strict subset of privacy consent — same fundamental requirements (informed + voluntary) PLUS CDR-specific overlays (granular per data set + per purpose, 12-month maximum, dashboard visibility, 2-business-day withdrawal). Privacy Act consent is more flexible (longer duration, less granular). Where they overlap, CDR rules typically prevail (more specific + more protective). ADRs handle CDR data under both regimes.

What happens to data after consent is withdrawn?

CDR rules require: ADR stops new data requests immediately, ceases use of existing data within 2 business days, EITHER deletes the data OR de-identifies it per CDR de-identification standard, updates dashboard. Some data may be retained where required by law (e.g. AML/CTF records, ASIC + ATO record-keeping requirements) — these exceptions documented in the privacy policy + consent flow.

Can ADR re-use the data for new purposes?

No. Specific consent is per-purpose. Using data for a NEW purpose requires NEW consent — even from existing customers. Common pattern: ADR maintains active consent for "cash-flow forecasting" + needs to add "lending serviceability assessment" — must run a fresh consent flow with the customer for the new purpose, get explicit consent, log the new consent in the dashboard.

How does XIntelliSync handle CDR consent?

XIntelliSync uses CDR data via accredited partners. The partner runs the consent flow (informed + voluntary + specific + current + time-bound + withdrawable) at the data holder + at the partner ADR. We receive the data downstream + use it ONLY for the purposes covered by the customer's consent. If the customer withdraws consent at the partner OR the data holder, the partner notifies us within 2 business days + we cease use of the data. Visibility: customer sees consents in CDR Dashboards at both bank + partner.