Quick answer
The Consumer Data Right (CDR) lets individuals and small businesses in Australia choose to share their banking data with accredited providers. For a business loan, it lets a lender receive read-only transaction data directly from your bank with your consent. The OAIC says CDR consent expires after 12 months, can be withdrawn at any time, and you can ask for data to be deleted when it's no longer needed.
Key points
- CDR is opt-in: you choose what's shared, with whom and for what.
- Data can only go to accredited businesses, which are listed on cdr.gov.au.
- Consent expires after 12 months and can be withdrawn through a dashboard.
- Data access is read-only — it doesn't let anyone move your money.
- Sectors live
- Banking and energy
- Consent limit
- 12 months
- Access type
- Read-only data
- Who can use it
- Individuals and small businesses
“Connect your bank” has become one of the most common steps in an online business loan application. For some owners it feels like the obvious, quick option. For others it feels like handing over the keys. Both reactions make sense, and the truth sits in the detail: what’s being shared, under which system, with whom, and for how long.
This page explains Australia’s Consumer Data Right in the context of business lending, so you can make an informed choice — and recognise when something doesn’t look right.
What is the Consumer Data Right?
The Consumer Data Right, or CDR, is an Australian government framework that lets people choose to share data held about them with accredited providers. According to cdr.gov.au, it’s an opt-in system that currently operates in banking and energy, with non-bank lending designated as the next sector to follow. It applies to individuals and small businesses.
In banking, CDR is what most people mean by “open banking”. It lets your bank send your transaction and account data securely to an accredited recipient you choose — such as a lender or a data service working for a lender — after you’ve given explicit consent.
What can and can’t be done with CDR data?
| CDR data sharing does | CDR data sharing doesn’t |
|---|---|
| Share read-only account and transaction data you choose | Give anyone the ability to make payments from your account |
| Send data only to accredited businesses | Allow your data to be shared without consent |
| Let you specify the purpose the data can be used for | Last forever — consent expires after 12 months |
| Give you a dashboard to manage and withdraw consent | Require you to give your banking password to the recipient |
The OAIC explains that you choose who can access your data, which kinds of data move and the purpose they may be used for — and that you can end the sharing whenever you like. You can also ask for your data to be deleted once it’s no longer needed.
How does a CDR connection work in a loan application?
A typical flow looks like this:
- The lender (or its data provider) explains what data it wants and why — for example, 12 months of transactions to assess your application.
- You’re redirected to your bank’s own website or app to log in and authorise the sharing. The recipient doesn’t see your password.
- You choose which accounts to share.
- The data arrives with the lender, ready for analysis.
- You can review or withdraw consent later from the recipient’s dashboard or your bank’s data-sharing settings.
Once the data arrives, it’s analysed in the same way as any bank statement — see how lenders read your bank statements.
Is every “connect your bank” option CDR?
No, and this matters. Some services collect bank data by asking you to enter your internet banking login into their own screen, then retrieving statements on your behalf. This is often called screen scraping. It’s still widely used in lending, but it works differently: you’re giving the login to a third party rather than authorising sharing through your bank.
Before you connect, look for:
- whether you’re redirected to your own bank to approve the sharing
- the name of the accredited recipient, which you can check on cdr.gov.au
- a clear explanation of what data is collected and for how long
- a way to withdraw consent later
If you’re unsure, ask the lender which method they use, or choose to upload PDF statements instead. We compare the options in open banking or PDF statements.
How do you stay safe when sharing bank data?
- Only start a data-sharing process from a link inside the application you started yourself, not from an unexpected email or text.
- Never give your banking password or a one-time code to anyone over the phone, by email or by SMS.
- Check the recipient’s name and accreditation if it’s a CDR connection.
- Share only the accounts the lender actually needs.
- Review active connections in your bank’s settings after the loan is decided, and withdraw any you no longer need.
Scammers increasingly imitate lenders and “verification” services. Our page on online loan scams covers the warning signs, and data security and privacy explains how legitimate lenders handle your information. If you’d like to talk through which sharing method suits you, start a quick enquiry and raise it on the call.
Why do lenders prefer a direct connection?
For lenders, data that arrives straight from the bank can’t have been edited, which removes a whole layer of fraud checks. It also arrives in a consistent format, so analysis is faster and more accurate. For you, that usually means fewer follow-up questions and a quicker answer. It’s one of the reasons online lenders can decide in hours rather than weeks for straightforward applications.
What should you do after the loan is decided?
Whatever the outcome, tidy up. Check your bank’s data-sharing settings for active connections and stop any you no longer need, unless the lender needs ongoing access for a facility such as a line of credit. Keep a note of what you shared, with whom and when. It takes five minutes and keeps your data footprint small.
Ready to apply with confidence?
Sharing bank data is easier when you know exactly what’s happening. Begin your online enquiry — it takes about a minute and doesn’t involve a credit check. Your details go to one specialist rather than a crowd of lenders, and that specialist will tell you which data the matched lender needs and how it’s collected before anything is shared. Accurate answers in the form help us get the right lender, and the right data request, on the first attempt.
Frequently asked questions
Does connecting my bank give the lender access to my money?
No. Data sharing provides read-only access to information such as transactions and balances. It doesn't let the lender make payments from your account. Repayment debits are set up separately through a direct debit authority you sign.
How do I stop sharing my data?
The OAIC says each accredited business must provide a dashboard where you can manage your CDR activity, withdraw consent and ask for your data to be deleted. Your bank also lets you see and stop active data sharing.
Is CDR the same as giving my banking password to an app?
No. Under CDR you authorise sharing with your bank directly and your password isn't handed to the recipient. Some services instead ask for your login to collect statements on your behalf, often called screen scraping. Understand which method is being used before you proceed.
Can I use CDR if I'm a company, not a person?
The CDR covers individuals and small businesses. How business accounts and authorised users are set up varies by bank, so check your bank's data-sharing settings if the option doesn't appear.
Do I have to use open banking to get a loan?
No. Most lenders also accept PDF statements downloaded from your internet banking. Open banking is usually just faster.