Who must comply with Consumer Data Right (CDR) participant accreditation + compliance?
The applicability test for Consumer Data Right (CDR) participant accreditation + compliance (ACCC and OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has industry: Banks & ADIs. Where the business has industry: Fintech (non-bank), check whether you are an accredited CDR data recipient.
What the obligation is
Banking, energy and (soon) non-bank lending data sharing — accredited participants must comply with privacy safeguards.
The Consumer Data Right (Pt IVD Competition and Consumer Act) and the CDR Rules require data holders to share consumer data on request and accredited data recipients to handle CDR data under the 13 Privacy Safeguards. ACCC + OAIC jointly enforce; CDR has its own incident notification regime distinct from NDB.
The applicability test
Applies when the business has industry: Banks & ADIs. Where the business has industry: Fintech (non-bank), check whether you are an accredited CDR data recipient.
How the regulator frames it: Designated data holders + accredited data recipients in banking, energy, and (in scope) non-bank lending and telecommunications.
What triggers it: Becoming a data holder or accredited recipient.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (1 of 35: yes; 1 of 35: only if a further fact applies; 33 of 35: no).
| Industry | Answer |
|---|---|
| Banks & ADIs | Yes |
| Fintech (non-bank) | Only if a further fact applies |
| No | 33 other industries |
Business structure and size
Structure does not change the answer in the 2 industries it can reach: for every structure the answer is "depends on size or structure".
Size does not change the answer in the 2 industries it can reach: at every size band the answer is "depends on size or structure".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in banks & adis with 6–19 employees, turnover $1M–$3M: applies. Industry: Banks & ADIs.
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires industry: Banks & ADIs.
- Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: check whether it applies. applies only if you are an accredited CDR data recipient.
When you need to check further
The engine shows this obligation as "check whether this applies" when a business has industry: Fintech (non-bank). It then applies only if you are an accredited CDR data recipient. That fact is not something Rules Mate can infer from industry, structure or size.
What you must do, and when
- When due
- Continuous; incident notification within 30 days.
- Frequency
- Ongoing
- Evidence to keep
- Accreditation, CDR Policy, Privacy Safeguard compliance documentation, incident register.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Civil penalties up to $10M / 3× benefit / 10% turnover (CDR, CCA s56EV) for serious breaches.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so do these 2: the engine uses the same rule for each.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
- Banking Code of Practice 2025: applies to 100% of the same businesses (35.0× the overall rate)
- Banking Executive Accountability Regime (BEAR) — pre-FAR: applies to 100% of the same businesses (35.0× the overall rate)
- Comply with the ePayments Code: applies to 100% of the same businesses (35.0× the overall rate)
- Consumer Credit Hardship Notice (NCC ss 72-73): applies to 100% of the same businesses (17.5× the overall rate)
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Australian Competition and Consumer Commission and Office of the Australian Information Commissioner.
ACCC: Competition and consumer regulator administering the Competition and Consumer Act 2010 and Australian Consumer Law, plus industry codes and infrastructure access regimes.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
CCA: Australia's competition + consumer protection law.
Free tools that help with this obligation:
Questions
- Who must comply with Consumer Data Right (CDR) participant accreditation + compliance?
- Applies when the business has industry: Banks & ADIs. Where the business has industry: Fintech (non-bank), check whether you are an accredited CDR data recipient.
- Does Consumer Data Right (CDR) participant accreditation + compliance apply to sole traders?
- Depends on size or structure. Looking in the 2 industries it can reach and every size band, the engine's answer for a sole trader is: depends on size or structure.
- Does Consumer Data Right (CDR) participant accreditation + compliance apply to businesses with 1–5 employees?
- Depends on size or structure (1–5 employees, turnover $100K–$1M).
- When is "Consumer Data Right (CDR) participant accreditation + compliance" due?
- Continuous; incident notification within 30 days.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.