WorldPrivacyAtlas
Laws by country

Sector-Specific Law

Consumer Data Right

CDR

Australia · Banking data sharing from July 1, 2020; energy from November 15, 2022

The CDR is an open-banking-style data portability right, and its privacy dimension is the part businesses under-read: thirteen legally binding Privacy Safeguards in Part IVD apply to CDR data INSTEAD of the Australian Privacy Principles, not alongside them, so an organization can be subject to two different privacy regimes depending on which data is in issue. The Safeguards are generally stricter than the APPs — notably a near-prohibition on sending CDR data overseas except in strictly limited circumstances, which contrasts sharply with APP 8's accountability model, and a positive duty to delete or de-identify CDR data when it is no longer needed or when the consumer asks. Participation is compulsory for designated data holders (banks, and energy retailers in the National Electricity Market above a customer threshold) and voluntary but accreditation-gated for data recipients, who must pass an ACCC accreditation process. Enforced jointly by the ACCC and the OAIC.

Competition and Consumer Act 2010 (Cth), Part IVD (inserted by the Treasury Laws Amendment (Consumer Data Right) Act 2019); Competition and Consumer (Consumer Data Right) RulesRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.