Skip to main content
Rules Mate

Do fintech (non-bank) businesses need to comply with CDR Banking (Open Banking) — major + non-major ADIs?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Only if

Only if you are an accredited CDR data recipient. Being in this industry makes the obligation worth checking (Industry: Fintech (non-bank)), but the trigger is a fact the industry alone does not settle.

The obligation in brief

Comply with CDR Banking (Open Banking) — major + non-major ADIs. Consumer Data Right (Banking) commenced for major banks July 2020, non-major banks July 2021. Data holders must share product + consumer data via accredited APIs.

Trigger: Being an ADI; becoming an ADR.

Why fintech (non-bank) get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 33 of those industries the answer for "Comply with CDR Banking (Open Banking) — major + non-major ADIs" is no. Fintech (non-bank) is one of the 2 where the answer is different: only if.

The deciding fact for fintech (non-bank) businesses: Industry: Fintech (non-bank); applies only if you are an accredited CDR data recipient.

About the industry: Non-bank financial technology businesses — neobanks, BNPL, payment processors, crypto exchanges.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires industry: Banks & ADIs).

Answer by business structure and size

Each cell is the engine's outcome for a business in fintech (non-bank) with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"Comply with CDR Banking (Open Banking) — major + non-major ADIs": outcome for fintech (non-bank) businesses by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderCheckCheckCheckCheckCheckCheck
PartnershipCheckCheckCheckCheckCheckCheck
TrustCheckCheckCheckCheckCheckCheck
Pty Ltd companyCheckCheckCheckCheckCheckCheck
Public companyCheckCheckCheckCheckCheckCheck
Not-for-profit (unregistered)CheckCheckCheckCheckCheckCheck
Registered charityCheckCheckCheckCheckCheckCheck
Super fundCheckCheckCheckCheckCheckCheck
Foreign companyCheckCheckCheckCheckCheckCheck

What the obligation requires

When due
Continuous; incident notification within 30 days.
Evidence to keep
CDR Register listing; consumer authorisation records; incident register.
Maximum penalty
Civil penalties up to $10M / 3× benefit / 10% turnover (CCA s56EV); ACCC + OAIC joint enforcement
Regulator
ACCC and OAIC
Jurisdiction
Commonwealth (national)

Other obligations where fintech (non-bank) differ from the norm

Other industries with a non-default answer

Questions

Do fintech (non-bank) businesses need to comply with CDR Banking (Open Banking) — major + non-major ADIs?
Only if you are an accredited CDR data recipient. Being in this industry makes the obligation worth checking (Industry: Fintech (non-bank)), but the trigger is a fact the industry alone does not settle.
Is the answer the same for every industry?
No. For 33 of the 35 industries Rules Mate maps, the answer is no. Fintech (non-bank) is one of 2 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.