Consumer Data Right (CDR) Framework (Australia)
Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CDR: Accreditation
Accreditation at the unrestricted level permits collection and use of CDR data subject to the full obligations.
- ACCC accreditation certificate (unrestricted)
- Ongoing eligibility evidence
- Operating without valid accreditation
Sponsored accreditation allows an entity to be accredited via a sponsor that takes on certain obligations.
- Sponsorship arrangement + sponsor obligations
- Sponsorship terms undefined
Affiliate accreditation permits a principal to extend accreditation to an affiliate under its responsibility.
- Affiliate arrangement + principal responsibility records
- Affiliate operating outside principal control
A CDR representative provides goods/services using CDR data under a principal accredited data recipient, governed by a CDR representative arrangement.
- CDR representative arrangement
- Principal oversight of the representative
- No CDR representative arrangement
Disclosures to trusted advisers, and CDR insight disclosures, must meet the rules' conditions.
- Trusted-adviser/insight disclosure controls per the rules
- Disclosures outside permitted classes
Action initiation (where enabled) requires the relevant accreditation and adherence to action-initiation rules.
- Action-initiator accreditation + action-initiation controls
- Initiating actions without accreditation
CDR: Consent and Authorisation
Consent to collect/use CDR data must be voluntary.
- Consent flows demonstrating voluntariness
- Coerced/bundled consent
Consent must be express (a clear affirmative act), not implied.
- Express-consent capture records
- Implied consent relied upon
Consumers must be given the information needed to understand what they are consenting to.
- Consent disclosures (data, purpose, recipients, duration)
- Insufficient information at consent
Consent must be specific as to the data, use and duration.
- Granular, specific consent capture
- Over-broad consent
Consent must be limited in time and re-sought on expiry.
- Consent expiry + re-consent mechanism
- Indefinite consent
Consumers must be able to withdraw consent (and data holders to manage authorisation withdrawal) easily via the dashboard, with prompt cessation.
- Easy withdrawal via dashboard + cessation records
- No easy withdrawal path
CDR: Privacy Safeguards (CCA Part IVD Div 5)
Accredited data recipients and data holders must manage CDR data in an open and transparent way, including by having and publishing a CDR policy.
- Published CDR policy
- Open-management procedures for CDR data
- No published CDR policy
Recipients must notify the consumer (dashboard) of disclosures of CDR data.
- Disclosure notifications via consumer dashboard
- No disclosure notification
Recipients must take reasonable steps to ensure CDR data they disclose is accurate, up to date and complete, having regard to the purpose.
- Data-quality assurance for disclosed CDR data
- Inaccurate CDR data disclosed
Recipients must protect CDR data from misuse, interference, loss and unauthorised access per the information-security requirements (Schedule 2), and destroy or de-identify redundant CDR data.
- Information-security controls per CDR Rules Schedule 2
- Destruction/de-identification of redundant CDR data
- CDR data not secured to Schedule 2
- Redundant data retained
Recipients must correct CDR data on request or notify the consumer of refusal, with reasons and complaint avenues.
- Correction request handling + refusal-with-reasons records
- Corrections not actioned
Where lawful and practicable, individuals must have the option of dealing anonymously or by pseudonym in relation to CDR data.
- Anonymity/pseudonymity options where practicable
- No anonymity option assessed
An accredited data recipient may only seek to collect CDR data with valid consent and only data reasonably needed.
- Consent-based collection scoped to need
- Collection beyond consented scope
If unsolicited CDR data is received, the recipient must determine whether it could have been collected under the rules and destroy/de-identify it if not.
- Unsolicited-data handling + destruction/de-identification records
- Unsolicited CDR data retained improperly
Recipients must notify the consumer (via the consumer dashboard) of the collection of CDR data.
- Collection notifications via consumer dashboard
- No collection notification
CDR data may only be used or disclosed in accordance with consent and the rules; otherwise prohibited.
- Use/disclosure controls bound to consent + rules
- Use/disclosure beyond consent
CDR data must not be used or disclosed for direct marketing except as permitted by the rules.
- Direct-marketing restriction controls
- CDR data used for direct marketing without permission
Before disclosing CDR data overseas, recipients must take reasonable steps to ensure the overseas recipient complies with the privacy safeguards (with accountability).
- Overseas-disclosure due diligence + contractual safeguards
- Overseas disclosure without safeguards
Recipients must not adopt, use or disclose a government related identifier of a consumer except as permitted.
- Controls preventing improper use of government identifiers
- Government identifiers used improperly
CDR: Rules, Security and Oversight
Recipients must respond to eligible data breaches and comply with notifiable-data-breach obligations (OAIC) for CDR data.
- CDR data-breach response + OAIC notification procedure
- No breach notification process for CDR data
Participants must maintain internal dispute resolution for CDR complaints and inform consumers of external avenues (OAIC/AFCA).
- Internal dispute resolution procedure + external-avenue disclosure
- No CDR complaints process
Participants must pass Conformance Test Suite testing and meet the CDR data standards before going live and on changes.
- CTS conformance results
- Standards-version compliance
- Non-conformant implementation
Data holders and recipients must provide consumer dashboards showing authorisations/consents and CDR receipts for transparency and control.
- Consumer dashboard + CDR receipts
- No consumer dashboard
The CDR applies to designated sectors (banking, energy, with telecommunications and others in development); data holders in a designated sector must share designated datasets.
- Determination of designated-sector status + in-scope datasets
- In-scope datasets not identified
Use of outsourced service providers for CDR data must be governed by a CDR outsourcing arrangement flowing down the obligations.
- CDR outsourcing arrangements with obligation flow-down
- OSP without a compliant arrangement
The ACCC administers the CDR rules/accreditation and the OAIC oversees privacy; both have enforcement powers.
- Procedures to respond to ACCC/OAIC oversight + reporting
- No process for regulator engagement
Accredited recipients must implement the information-security controls in Schedule 2 of the CDR Rules (governance, access, monitoring, encryption, testing) and report assurance.
- Schedule 2 information-security control implementation
- Annual assurance report / attestation
- Schedule 2 controls not implemented
- No assurance reporting
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Consumer Data Right (CDR) Framework (Australia) framework page.