Logo
  • Overview
  • Consent
  • Authenticate
  • Authorise
  • Consent Management
  • Notifications
Consumer Experience (CX) Guidelines

Authorisation to disclose joint account data

These guidelines provide examples for how to implement the authorisation flow in relation to joint accounts.
‣
On this page

Overview

According to rule 1.7, a joint account is a joint account with a data holder for which there are 2 or more joint account holders, each of which is an individual who:

(i) so far as the data holder is aware, is acting in their own capacity and not on behalf of another person; and

(ii) is eligible in relation to the data holder; but does not include a partnership account with a data holder.

Division 4.2A sets out the three disclosure options (pre-approval option, co-approval option and non-disclosure option), with the default option being the pre-approval option.

The guidelines in this section provide examples of how to implement requirements for the authorisation flow for disclosing data from joint accounts.

For further guidance, see ACCC's Revised joint account implementation guidance.

Authorise is the third stage of
Authorise is the third stage of The Consent Model.

Wireframes and guidelines

icon

Note: The wireframes shown are examples of how to implement key rules, standards, and guidelines. Use the on-screen functions to adjust zoom level or expand the wireframes to be viewed at full screen.

Default example (pre-approval option)

The following wireframes show a basic example of the authorisation flow where account holder A (AH-A) authorises to share data from a joint account with pre-approval disclosure option. Variations can be found in the below sections.

Note: Other requirements related to authorisation apply to this flow. Check the latest CDR Rules, CX Standards and Guidelines on authorisation for guidance.

‣
See key requirements and guidelines
‣
See prototype

Authorisation flow for vulnerable requesters

The following wireframes show an example of the authorisation flow where rule 4A.15 is leveraged to allow account holder A (AH-A), a vulnerable requester, to share their joint account data as if it were an individual account.

The standards and guidelines outlined below represent one possibility for supporting vulnerable consumers. This may apply, for example, where the Data Holder recognises that notifying the other joint account holder(s) of joint account sharing may put a vulnerable requester at risk.

This approach may not be appropriate for other scenarios concerning vulnerability. Data Holders should assess the appropriateness of this optional implementation pattern based on their existing protocols for dealing with vulnerability.

‣
See wireframes, key requirements and guidelines

Authorisation flow with co-approval joint accounts

The following wireframes show an example where account holder A (AH-A) authorises to share data from a joint account with co-approval disclosure option, requiring account holder B (AH-B) to respond to this request before data from the joint account can be accessed.

‣
See wireframes, key requirements and guidelines

Download open source asset

Open sources design assets are created in Figma for the purposes of assisting implementation. This Figma file contains annotated wireframes and working prototypes for Authorisation to disclose joint account data, including:

  • Default example (pre-approval option)
  • Authorisation flow for vulnerable requester
  • Authorisation flow with co-approval joint accounts
icon
Download design asset
Item
File
Date released
Version introduced
3AU2. Authorisation to disclose joint account data v1.35.0.2025.09.12
3AU2. Authorisation to disclose joint account data v1.35.0.2025.09.12.fig
Sep 12, 2025
1.35.0

For past versions, refer to Change log.

‣
About open source assets

About this page

References

The artefacts on this page were informed by the following sources.

Title
Author
Date published
URL
Type
Change Request 700: CX Guidelines | Redirect to App (R2A) CX Guidelines Changes
Data Standards Body (DSB)
Jun 5, 2025
github.com
Consultations
Consultation Draft 369: Redirect to App - Draft Standards
Data Standards Body (DSB)
Apr 4, 2025
github.com
Consultations
Joint account implementation guidance
Australian Competition and Consumer Commission (ACCC)
Feb 4, 2025
www.cdr.gov.au
Guidance
Noting Paper 207: Draft v3 Rules Analysis | Anticipated Data Standards
Data Standards Body (DSB)
Aug 4, 2021
github.com
Consultations
Draft v3 Rules consultation
The Treasury
Jul 1, 2021
treasury.gov.au
Consultations
Design Paper 176: an ‘opt-out’ data sharing model for joint accounts in the banking and energy sectors
Data Standards Body (DSB)
Apr 26, 2021
github.com
Consultations
Decision Proposal 162: CX Standards | Joint Accounts (see concept Authorisation flow)
Data Standards Body (DSB)
Feb 15, 2021
github.com
Consultations
Noting Paper 157: CX Standards Arising from v2 Rules
Data Standards Body (DSB)
Jan 29, 2021
github.com
Consultations
Report 2: Joint Accounts and the Consumer Data Right
Consumer Policy Research Centre (CPRC)
Dec 1, 2020
cx.dsb.gov.au
Research
Draft v2 Rules consultation (see concept 7.1 Joint accounts)
Australian Competition and Consumer Commission (ACCC)
Nov 18, 2020
accc.gov.au
Consultations
Phase 3, Round 3 Research Report
Data Standards Body (DSB)
Aug 31, 2020
cx.dsb.gov.au
Research
Phase 3, Round 1 and 2 Research Report
Data Standards Body (DSB)
Aug 31, 2020
cx.dsb.gov.au
Research
Phase 3, Round 6 Research Report
Data Standards Body (DSB)
Aug 31, 2020
cx.dsb.gov.au
Research
CX Workshop: Joint Accounts
Data Standards Body (DSB)
Aug 1, 2019
miro.com
Consultations
Phase 2, Stream 1 Research Report
GippsTech
Jul 31, 2019
cx.dsb.gov.au
Research
10 Usability Heuristics for User Interface Design (Visibility of system status)
Nielsen Norman Group (NNG)
Apr 24, 1994
nngroup.com
Other

Last updated

This page was updated @Sep 12, 2025

Have your say

Community consultations and maintenance are part of our ongoing process. Here’s how you can get involved:

  • Request new Guidelines or changes to existing Guidelines through the CX Guidelines Consultation process
  • Request new Standards or changes to existing Standards through the Standards Maintenance process
  • Log a ticket for any questions about the rules, standards, or guidelines through the CDR Support Portal
  • Email your feedback to cx@dsb.gov.au
image

Quick links to CX Guidelines:

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Accessibility statement

→ cx@dsb.gov.au → cx.dsb.gov.au | cds.gov.au

The Consumer Data Standards Program is part of Treasury. Copyright © Commonwealth of Australia 2023. The information provided on this website is licensed for re-distribution and re-use in accordance with Creative Commons Attribution 4.0 International (CC-BY 4.0) Licence.
Data Standards Body | CX Guidelines

CX Guidelines

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Keep in touch

DSB Newsletter

Website use

Accessibility Statement

Copyright

Privacy

Disclaimer

In the spirit of reconciliation, the Data Standards Body acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples.