Sector-Specific Law
Consumer Data Right
Australia · Banking data sharing from July 1, 2020; energy from November 15, 2022
The CDR is an open-banking-style data portability right, and its privacy dimension is the part businesses under-read: thirteen legally binding Privacy Safeguards in Part IVD apply to CDR data INSTEAD of the Australian Privacy Principles, not alongside them, so an organization can be subject to two different privacy regimes depending on which data is in issue. The Safeguards are generally stricter than the APPs — notably a near-prohibition on sending CDR data overseas except in strictly limited circumstances, which contrasts sharply with APP 8's accountability model, and a positive duty to delete or de-identify CDR data when it is no longer needed or when the consumer asks. Participation is compulsory for designated data holders (banks, and energy retailers in the National Electricity Market above a customer threshold) and voluntary but accreditation-gated for data recipients, who must pass an ACCC accreditation process. Enforced jointly by the ACCC and the OAIC.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.