Does Consumer Data Right (CDR) participant accreditation + compliance apply to banks and ADIs?
A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.
Short answer: Yes
Yes. This obligation applies to banks and ADIs whatever their structure or size. The deciding fact: Industry: Banks & ADIs.
The obligation in brief
Consumer Data Right (CDR) participant accreditation + compliance. The Consumer Data Right (Pt IVD Competition and Consumer Act) and the CDR Rules require data holders to share consumer data on request and accredited data recipients to handle CDR data under the 13 Privacy Safeguards. ACCC + OAIC jointly enforce; CDR has its own incident notification regime distinct from NDB.
Trigger: Becoming a data holder or accredited recipient.
Why banks & adis get a different answer
Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 33 of those industries the answer for "Consumer Data Right (CDR) participant accreditation + compliance" is no. Banks & ADIs is one of the 2 where the answer is different: yes.
The deciding fact for banks and ADIs: Industry: Banks & ADIs.
About the industry: Authorised deposit-taking institutions regulated by APRA under the Banking Act 1959.
Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires industry: Banks & ADIs).
Answer by business structure and size
Each cell is the engine's outcome for a business in banks & adis with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.
| Structure | No employees | 1–5 employees | 6–19 employees | 20–99 employees | 100–499 employees | 500+ employees |
|---|---|---|---|---|---|---|
| Sole trader | Yes | Yes | Yes | Yes | Yes | Yes |
| Partnership | Yes | Yes | Yes | Yes | Yes | Yes |
| Trust | Yes | Yes | Yes | Yes | Yes | Yes |
| Pty Ltd company | Yes | Yes | Yes | Yes | Yes | Yes |
| Public company | Yes | Yes | Yes | Yes | Yes | Yes |
| Not-for-profit (unregistered) | Yes | Yes | Yes | Yes | Yes | Yes |
| Registered charity | Yes | Yes | Yes | Yes | Yes | Yes |
| Super fund | Yes | Yes | Yes | Yes | Yes | Yes |
| Foreign company | Yes | Yes | Yes | Yes | Yes | Yes |
What the obligation requires
- When due
- Continuous; incident notification within 30 days.
- Evidence to keep
- Accreditation, CDR Policy, Privacy Safeguard compliance documentation, incident register.
- Maximum penalty
- Civil penalties up to $10M / 3× benefit / 10% turnover (CDR, CCA s56EV) for serious breaches
- Regulator
- ACCC and OAIC
- Jurisdiction
- Commonwealth (national)
Other obligations where banks & adis differ from the norm
- Comply with credit reporting obligations (Part IIIA Privacy Act): Yes
- APP 2 — anonymity + pseudonymity for individuals: Yes
- Comply with APRA CPS 220 (Risk Management): Yes
- Comply with APRA CPS 230 (Operational Risk Management): Yes
- Comply with APRA CPS 234 (Information Security): Yes
- Comply with Australian sanctions law + screening (DFAT): Yes
- All 32 answers for banks & adis
Other industries with a non-default answer
Questions
- Does Consumer Data Right (CDR) participant accreditation + compliance apply to banks and ADIs?
- Yes. This obligation applies to banks and ADIs whatever their structure or size. The deciding fact: Industry: Banks & ADIs.
- Is the answer the same for every industry?
- No. For 33 of the 35 industries Rules Mate maps, the answer is no. Banks & ADIs is one of 2 industries with a different answer.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.