Skip to content

Evidence request lists

Consumer Data Right (CDR) Framework (Australia)

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CDR: Accreditation

CDR-ACC-1
Unrestricted Accreditation

Accreditation at the unrestricted level permits collection and use of CDR data subject to the full obligations.

Artefacts an auditor will ask for
  • ACCC accreditation certificate (unrestricted)
  • Ongoing eligibility evidence
Where this commonly fails
  • Operating without valid accreditation
CDR-ACC-2
Sponsored Accreditation

Sponsored accreditation allows an entity to be accredited via a sponsor that takes on certain obligations.

Artefacts an auditor will ask for
  • Sponsorship arrangement + sponsor obligations
Where this commonly fails
  • Sponsorship terms undefined
CDR-ACC-3
Affiliate Accreditation

Affiliate accreditation permits a principal to extend accreditation to an affiliate under its responsibility.

Artefacts an auditor will ask for
  • Affiliate arrangement + principal responsibility records
Where this commonly fails
  • Affiliate operating outside principal control
CDR-ACC-4
CDR Representative Model

A CDR representative provides goods/services using CDR data under a principal accredited data recipient, governed by a CDR representative arrangement.

Artefacts an auditor will ask for
  • CDR representative arrangement
  • Principal oversight of the representative
Where this commonly fails
  • No CDR representative arrangement
CDR-ACC-5
Trusted Adviser and Insight Disclosure

Disclosures to trusted advisers, and CDR insight disclosures, must meet the rules' conditions.

Artefacts an auditor will ask for
  • Trusted-adviser/insight disclosure controls per the rules
Where this commonly fails
  • Disclosures outside permitted classes
CDR-ACC-6
Accredited Action Initiator

Action initiation (where enabled) requires the relevant accreditation and adherence to action-initiation rules.

Artefacts an auditor will ask for
  • Action-initiator accreditation + action-initiation controls
Where this commonly fails
  • Initiating actions without accreditation

CDR: Consent and Authorisation

CDR-CON-1
Voluntary Consent

Consent to collect/use CDR data must be voluntary.

Artefacts an auditor will ask for
  • Consent flows demonstrating voluntariness
Where this commonly fails
  • Coerced/bundled consent
CDR-CON-2
Express Consent

Consent must be express (a clear affirmative act), not implied.

Artefacts an auditor will ask for
  • Express-consent capture records
Where this commonly fails
  • Implied consent relied upon
CDR-CON-3
Informed Consent

Consumers must be given the information needed to understand what they are consenting to.

Artefacts an auditor will ask for
  • Consent disclosures (data, purpose, recipients, duration)
Where this commonly fails
  • Insufficient information at consent
CDR-CON-4
Specific Consent

Consent must be specific as to the data, use and duration.

Artefacts an auditor will ask for
  • Granular, specific consent capture
Where this commonly fails
  • Over-broad consent
CDR-CON-5
Time-Limited Consent

Consent must be limited in time and re-sought on expiry.

Artefacts an auditor will ask for
  • Consent expiry + re-consent mechanism
Where this commonly fails
  • Indefinite consent
CDR-CON-6
Withdrawable Consent and Authorisation

Consumers must be able to withdraw consent (and data holders to manage authorisation withdrawal) easily via the dashboard, with prompt cessation.

Artefacts an auditor will ask for
  • Easy withdrawal via dashboard + cessation records
Where this commonly fails
  • No easy withdrawal path

CDR: Privacy Safeguards (CCA Part IVD Div 5)

CDR-PS-1
Privacy Safeguard 1: Open and Transparent Management of CDR Data

Accredited data recipients and data holders must manage CDR data in an open and transparent way, including by having and publishing a CDR policy.

Artefacts an auditor will ask for
  • Published CDR policy
  • Open-management procedures for CDR data
Where this commonly fails
  • No published CDR policy
CDR-PS-10
Privacy Safeguard 10: Notifying of the Disclosure of CDR Data

Recipients must notify the consumer (dashboard) of disclosures of CDR data.

Artefacts an auditor will ask for
  • Disclosure notifications via consumer dashboard
Where this commonly fails
  • No disclosure notification
CDR-PS-11
Privacy Safeguard 11: Quality of CDR Data

Recipients must take reasonable steps to ensure CDR data they disclose is accurate, up to date and complete, having regard to the purpose.

Artefacts an auditor will ask for
  • Data-quality assurance for disclosed CDR data
Where this commonly fails
  • Inaccurate CDR data disclosed
CDR-PS-12
Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification

Recipients must protect CDR data from misuse, interference, loss and unauthorised access per the information-security requirements (Schedule 2), and destroy or de-identify redundant CDR data.

Artefacts an auditor will ask for
  • Information-security controls per CDR Rules Schedule 2
  • Destruction/de-identification of redundant CDR data
Where this commonly fails
  • CDR data not secured to Schedule 2
  • Redundant data retained
CDR-PS-13
Privacy Safeguard 13: Correction of CDR Data

Recipients must correct CDR data on request or notify the consumer of refusal, with reasons and complaint avenues.

Artefacts an auditor will ask for
  • Correction request handling + refusal-with-reasons records
Where this commonly fails
  • Corrections not actioned
CDR-PS-2
Privacy Safeguard 2: Anonymity and Pseudonymity

Where lawful and practicable, individuals must have the option of dealing anonymously or by pseudonym in relation to CDR data.

Artefacts an auditor will ask for
  • Anonymity/pseudonymity options where practicable
Where this commonly fails
  • No anonymity option assessed
CDR-PS-3
Privacy Safeguard 3: Seeking to Collect CDR Data from CDR Participants

An accredited data recipient may only seek to collect CDR data with valid consent and only data reasonably needed.

Artefacts an auditor will ask for
  • Consent-based collection scoped to need
Where this commonly fails
  • Collection beyond consented scope
CDR-PS-4
Privacy Safeguard 4: Dealing with Unsolicited CDR Data

If unsolicited CDR data is received, the recipient must determine whether it could have been collected under the rules and destroy/de-identify it if not.

Artefacts an auditor will ask for
  • Unsolicited-data handling + destruction/de-identification records
Where this commonly fails
  • Unsolicited CDR data retained improperly
CDR-PS-5
Privacy Safeguard 5: Notifying of the Collection of CDR Data

Recipients must notify the consumer (via the consumer dashboard) of the collection of CDR data.

Artefacts an auditor will ask for
  • Collection notifications via consumer dashboard
Where this commonly fails
  • No collection notification
CDR-PS-6
Privacy Safeguard 6: Use or Disclosure of CDR Data

CDR data may only be used or disclosed in accordance with consent and the rules; otherwise prohibited.

Artefacts an auditor will ask for
  • Use/disclosure controls bound to consent + rules
Where this commonly fails
  • Use/disclosure beyond consent
CDR-PS-7
Privacy Safeguard 7: Use or Disclosure of CDR Data for Direct Marketing

CDR data must not be used or disclosed for direct marketing except as permitted by the rules.

Artefacts an auditor will ask for
  • Direct-marketing restriction controls
Where this commonly fails
  • CDR data used for direct marketing without permission
CDR-PS-8
Privacy Safeguard 8: Overseas Disclosure of CDR Data

Before disclosing CDR data overseas, recipients must take reasonable steps to ensure the overseas recipient complies with the privacy safeguards (with accountability).

Artefacts an auditor will ask for
  • Overseas-disclosure due diligence + contractual safeguards
Where this commonly fails
  • Overseas disclosure without safeguards
CDR-PS-9
Privacy Safeguard 9: Adoption or Disclosure of Government Related Identifiers

Recipients must not adopt, use or disclose a government related identifier of a consumer except as permitted.

Artefacts an auditor will ask for
  • Controls preventing improper use of government identifiers
Where this commonly fails
  • Government identifiers used improperly

CDR: Rules, Security and Oversight

CDR-RULE-BREACH
CDR Data Breach and Notifiable Data Breach

Recipients must respond to eligible data breaches and comply with notifiable-data-breach obligations (OAIC) for CDR data.

Artefacts an auditor will ask for
  • CDR data-breach response + OAIC notification procedure
Where this commonly fails
  • No breach notification process for CDR data
CDR-RULE-COMPLAINTS
Complaints and Internal Dispute Resolution

Participants must maintain internal dispute resolution for CDR complaints and inform consumers of external avenues (OAIC/AFCA).

Artefacts an auditor will ask for
  • Internal dispute resolution procedure + external-avenue disclosure
Where this commonly fails
  • No CDR complaints process
CDR-RULE-CONFORMANCE
Conformance Testing (CTS)

Participants must pass Conformance Test Suite testing and meet the CDR data standards before going live and on changes.

Artefacts an auditor will ask for
  • CTS conformance results
  • Standards-version compliance
Where this commonly fails
  • Non-conformant implementation
CDR-RULE-DASHBOARD
Consumer Dashboards and Receipts

Data holders and recipients must provide consumer dashboards showing authorisations/consents and CDR receipts for transparency and control.

Artefacts an auditor will ask for
  • Consumer dashboard + CDR receipts
Where this commonly fails
  • No consumer dashboard
CDR-RULE-DESIGNATION
Sector Designation and Scope

The CDR applies to designated sectors (banking, energy, with telecommunications and others in development); data holders in a designated sector must share designated datasets.

Artefacts an auditor will ask for
  • Determination of designated-sector status + in-scope datasets
Where this commonly fails
  • In-scope datasets not identified
CDR-RULE-OSP
Outsourced Service Provider Arrangements

Use of outsourced service providers for CDR data must be governed by a CDR outsourcing arrangement flowing down the obligations.

Artefacts an auditor will ask for
  • CDR outsourcing arrangements with obligation flow-down
Where this commonly fails
  • OSP without a compliant arrangement
CDR-RULE-OVERSIGHT
Regulator Oversight and Enforcement (ACCC and OAIC)

The ACCC administers the CDR rules/accreditation and the OAIC oversees privacy; both have enforcement powers.

Artefacts an auditor will ask for
  • Procedures to respond to ACCC/OAIC oversight + reporting
Where this commonly fails
  • No process for regulator engagement
CDR-RULE-SECURITY
Information Security (CDR Rules Schedule 2)

Accredited recipients must implement the information-security controls in Schedule 2 of the CDR Rules (governance, access, monitoring, encryption, testing) and report assurance.

Artefacts an auditor will ask for
  • Schedule 2 information-security control implementation
  • Annual assurance report / attestation
Where this commonly fails
  • Schedule 2 controls not implemented
  • No assurance reporting
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Consumer Data Right (CDR) Framework (Australia) framework page.