Consumer Data Right Rules 2020 (selected operational obligations)
Evidence request list. 9 controls, 9 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Selected CDR Rules obligations
Obtain and maintain accreditation, meeting the fit-and-proper, information security and other accreditation criteria before collecting CDR data.
- Accreditation status and number
- Evidence accreditation criteria are maintained
- Collecting CDR data without accreditation
- Accreditation criteria lapsed
Obtain valid, informed consent for collection, use and disclosure, give the consumer the recipient's name and accreditation number, allow withdrawal at any time, and provide a CDR receipt.
- Consent flow meeting CDR Rules Part 4
- CDR receipts issued
- Withdrawal mechanism
- Consent not informed or granular
- No CDR receipt
- No easy withdrawal
Only collect and use the CDR data required to provide the requested product or service.
- Mapping of collected data to product/service need
- Evidence of minimisation in consent design
- Collecting more data than needed
- Use beyond the stated purpose
Maintain a CDR policy that consumers can easily understand and access, covering how data is managed and how to make an enquiry or complaint.
- Published, accessible CDR policy
- Required content per OAIC guide
- No CDR policy
- Policy hard to access or incomplete
Inform consumers of their right to have redundant data deleted and delete or de-identify redundant CDR data accordingly.
- Deletion/de-identification on request
- Notice of deletion right
- Records of deletions
- Redundant data retained
- Deletion right not communicated
Maintain the records required by CDR Rule 9.3(2), including consents, withdrawals, complaints, deletions, use of data, de-identification, information security records, terms and conditions, and OSP/sponsor/representative arrangements.
- Record set per Rule 9.3(2)
- Consent and complaint records
- Information security records
- Required records not kept
- Incomplete consent/complaint records
Submit reports twice a year to the ACCC and OAIC (per CDR Rule 9.4) and provide a confirmation statement and verification report.
- Bi-annual ACCC/OAIC reports
- Confirmation statement and verification report
- Reports not submitted
- Confirmation/verification report missing
Maintain processes to receive and handle CDR consumer complaints and record complaint data.
- Complaints handling procedure
- Complaint records and outcomes
- No complaints process
- Complaints not recorded
Govern CDR outsourced service provider (OSP), sponsor, affiliate and CDR representative arrangements, including contractual controls and oversight.
- OSP/representative agreements with CDR controls
- Oversight of arrangements
- Records of arrangements
- OSP arrangements ungoverned
- No contractual CDR controls
- No oversight of representatives
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.