Open banking allows an eligible customer to direct that specified banking data be shared with an accredited provider through Australia’s Consumer Data Right. It is designed as a controlled data transfer, not as a request to hand over an internet-banking password or provide screen access to an unknown service.
The system is opt-in. A customer chooses whether to use it, which data is shared, for what purpose and for how long, subject to the framework. That consent can support services such as account aggregation, budgeting or product comparison, while the privacy safeguards impose obligations on participating businesses.
Consent is specific, not unlimited
The process begins through the accredited provider’s app or website. The customer is redirected to authenticate with the existing data holder and select eligible accounts and data. The accredited provider should not need the customer’s banking password, and credentials are not meant to be disclosed to it.
A consent request needs to explain the data sought, how it will be used, the sharing period and relevant disclosures. A broad request may be convenient, but customers can consider whether every category is necessary for the service. More data and a longer period increase the information exposed if something later goes wrong.
Consent is not ownership transfer. The data remains subject to rules about collection, use, disclosure, security, correction and deletion or de-identification. Participating businesses provide dashboards so consumers can view and manage relevant consents.
Accreditation and privacy safeguards create the boundary
The ACCC accredits data recipients and maintains the relevant register, while the system also supports authorised representatives and other participation models under the rules. A familiar brand or polished app is not enough; the CDR flow and provider status can be checked through official channels.
The OAIC explains thirteen privacy safeguards covering matters such as transparency, consent, notification, data quality, security and correction. CDR data cannot simply be used for any purpose a business later finds useful. Direct marketing and overseas disclosure have specific controls.
The Consumer Data Right is different from ordinary data sharing outside the scheme. Uploading a statement, granting email access or supplying login credentials to a comparison service may be governed by other privacy and contract arrangements. Customers need to know which process they are actually using.
Manage permissions after the service begins
A consumer dashboard should show active consents and allow them to be managed. Ending a consent stops future collection, but the treatment of data already held depends on the rules, consent and any lawful retention obligation. The provider’s CDR policy should explain deletion and de-identification options.
Review permissions when a budgeting app is no longer used, accounts are closed or the original purpose has ended. Keep devices and email secure because access to an app or dashboard can expose sensitive financial information even when the underlying data transfer is protected.
If data appears wrong, the framework includes correction mechanisms. If a participant mishandles CDR data, complaint pathways can include the business itself, external dispute resolution and the OAIC depending on the issue. Records of the consent and problem help establish what occurred.
Open banking can reduce friction and support useful tools, but the safest consent is one the customer understands and still needs. Periodic permission review is the data equivalent of reviewing direct debits on a bank account.
Joint accounts and business accounts can add authority questions. The rules and data holder processes determine who can nominate users or authorise sharing, and not every account is immediately eligible. An app failing to display an account does not justify bypassing the CDR process by giving away credentials. The provider and bank can explain whether the account, customer type and authority are supported.
Product data is another part of the system. Standardised information about rates, fees and features can support comparison even without sharing a person’s transaction history. Consumer data enables more tailored services, but it is also more sensitive. Knowing which type the app requests helps the customer judge whether the access is proportionate.
Before connecting a service, read how it earns money. A free budgeting tool may have a commercial model involving referrals or additional products. CDR controls how data is handled within the framework, but it does not make every recommendation independent or suitable. Privacy protection and product judgement remain separate questions.
This article provides general information only and is not personal financial, privacy or legal advice. The CDR rules, participating sectors and provider arrangements can change, so current official information should be checked.
