Logo
  • Overview
  • Consent
  • Authenticate
  • Authorise
  • Consent Management
  • Notifications
Consumer Experience (CX) Guidelines
/
Consent Management
/
Consent Management (Data holder)
/
Joint account notification settings
/
CX Guidelines

CX Guidelines

Read first CX Checklist attributes ◦ Area refers to the stage in the consumer journey, such as Pre-consent, Consent, Authenticate, Authorise, or Consent Management. ◦ Focus area refers to a specific theme in each stage (e.g. 01. User Identifier). ◦ Checklist ref contains a unique reference number for the item. ▪ The first values refer to the Area (e.g. 0DL.xx.xx for data language; 2AU.xx.xx for authentication). ▪ The second set values refer to the Focus area (e.g. xxx.01.xx). ▪ The last values refer to the annotation number used on the wireframe, where available (e.g. xxx.xx.02; wireframes are linked to in the Example column). ◦ Type refers to the source of the statement: Rules, Standards and Guidelines. ◦ Participant refers to the relevant CDR Participant for the item. ◦ Requirement level refers to the level of obligation. For the data standards, the key words MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY are to be interpreted as described in RFC2119. CX Guidelines provide optional examples and recommendations; as such, a MAY is used to denote a CX Guideline for the purposes of this checklist regardless of the language used in the guideline statement. ◦ Statement refers to the relevant requirement or recommendation as articulated in the rules, standards, or guidelines. ◦ References points to the requirement itself, or its location; typically a rule, standard, or research. ◦ Example links to the relevant artefact, such as the CX Guideline page, which includes wireframes of example implementations, or a table in the case of data language standards. ◦ Version introduced refers to the version of the data standards that was current when the item was introduced to the CX Guidelines, starting from version 1.4.0. Items noted as introduced in 1.4.0 or earlier are requirements that exist in v1.4.0 of the CX Guidelines (PDF). ◦ Date introduced refers to the specific date the item was introduced to the CX Checklist, using August 2020 as a starting point (when v1.4.0 was introduced). The date will typically be the date of the version release, but some new items may not constitute a standards change (e.g. a revised wireframe or rules change) and as such may not align with standards versioning. ◦ Date modified refers to when an existing CX Checklist entry was updated, which is not necessarily the date the corresponding requirement (Rule, Standard or Guideline) was changed. ◦ Status refers to whether the item is active or has been retired from the CX Guidelines. An 'active' item is applicable and current. A 'retired' item may be labelled as such because it no longer applies, has been merged with another item, or has been removed from the CX Guidelines. A 'retired' item may still be a requirement. These statuses are used in the live CX Checklist and CSV to highlight changes between versions of the CX Guidelines.
Wireframe ref
Type
Requirement level
Statement
Reference
Checklist ref
Focus area

01

CDR Rule
MUST

(1) For this rule, an approval notification is a notice given by the data holder: (a) to a relevant account holder, to inform them that the requester has given, amended or withdrawn an authorisation, or that the authorisation has expired; in accordance with the data standards.

CDR Rule 4A.14(1)(a)

5CM5.01.01

01. Joint account notifications

02

CDR Rule
MUST

(1) For this rule, an approval notification is a notice given by the data holder: (b) to the requester, to inform them that: (ii) a relevant account holder has withdrawn an approval previously given; in accordance with the data standards.

CDR Rule 4A.14(1)(b)(ii)

5CM5.01.02

01. Joint account notifications

03

CDR Rule
MUST

(1) For this rule, an approval notification is a notice given by the data holder: (b) to the requester, to inform them that: (i) one or more of the relevant account holders has not given their approval for disclosure within the time frame referred to in paragraph 4A.11(e); in accordance with the data standards.

CDR Rule 4A.14(1)(b)(i)

5CM5.01.03

01. Joint account notifications

04

CDR Rule
MUST

(3) The data holder must, in accordance with any relevant data standards: (a) provide for alternative notification schedules (including reducing the frequency of notifications or not receiving notifications); and (b) give each joint account holder a means of selecting such an alternative, and of changing a selection.

CDR Rule 4A.14(3)

5CM5.01.04

01. Joint account notifications

05

CX Standard
MAY

Data holders MAY allow a consumer to amend their notification schedule in line with existing notification management channels and experiences. This MAY, for example, allow the joint account notification schedule to be amended in the same location as other notifications.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Amendment channels

5CM5.01.05

01. Joint account notifications

06

CX Standard
MAY

For the content of the approval notification, data holders MAY provide the consumer with instructions for how any relevant authorisation(s) or approval(s) can be reviewed.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Notification content

5CM5.01.06

01. Joint account notifications

07

CX Standard
MAY

Data holders MAY provide a mechanism or entry point for a notification schedule to be amended from or in relation to the notification itself. This MAY, for example, allow a consumer to stop receiving the type of notification(s) from the notification itself. The notification MAY also, for example, include a link to amend the notification schedule or instructions to direct the consumer to the appropriate place.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Contextual amendment

5CM5.01.07

01. Joint account notifications

08

CX Standard
MAY

In relation to the joint account alert standards in this section, data holders MAY provide further information about any services or processes in place for supporting vulnerable consumers or reporting risks of physical, psychological, or financial harm or abuse to the data holder.

Notification Standards, Notifications: Joint Account Alerts, Joint account notifications: Further information

5CM5.01.08

01. Joint account notifications

09

CX Standard
MAY

Data holders MAY offer consumers the ability to specify which joint account notifications they do and do not want to receive. This MAY, for example, allow a relevant joint account holder to only receive notifications when the requester gives or amends an authorisation.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Granular control

5CM5.01.09

01. Joint account notifications

10

CX Standard
MAY

Data holders MAY allow consumers to elect to no longer receive any joint account notifications.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Turn off notifications

5CM5.01.10

01. Joint account notifications

11

CX Standard
MAY

Data holders MAY offer consumers the ability to receive their joint account notifications less frequently and as a periodic summary. This MAY, for example, outline all joint account activity at a frequency determined by the data holder and consumer, such as the previous quarter, month, fortnight, and so on. This MAY also, for example, be provided with or in relation to other CDR notifications such as a CDR Receipt, which is optional for data holders.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Reduced frequency

5CM5.01.11

01. Joint account notifications

12

CX Standard
MAY

Data holders MAY inform the consumer of the consequences of amending their joint account notification schedule. This notification MAY include instructions for how to amend this schedule or reverse the amendment.

Notification Standards, Alternative Notification Schedules for Joint Accounts, Joint account notifications: Consequences of amendment

5CM5.01.12

01. Joint account notifications

13

CX Guideline
MAY

CDR Rule 4A.14(3) requires data holders to: (a) provide for alternative notification schedules (including reducing the frequency of notifications or not receiving notifications), and (b) give each joint account holder a means of selecting such an alternative, and of changing an election. Alternative settings under rule 4A.14(3) only apply to the following notifications in rule 4A.14(1): 1. The requester has given, amended, or withdrawn an authorisation 2. Expiration of an authorisation 3. A relevant account holder hasn’t given approval within the relevant time frame 4. A relevant account holder has withdrawn an approval The standards in this section provide a non-exhaustive list of options that data holders may implement to support their compliance with these rules. The specific implementation of an alternative notification schedule and offering, which may or may not include options listed here, are at the data holder’s discretion. It is the data holder’s responsibility to ensure it is meeting its obligations under the CDR Rules. Compliance with the CDR Rules on alternative notification schedules would require, at a minimum, implementation of a combination of options (being a combination of options listed below, other measures, or both).

CDR Rule 4A.14(1), (3)

5CM5.01.13

01. Joint account notifications

14

CX Guideline
MAY

Data holders may offer an alternative notification schedule to apply at the account level and the customer level.

5CM5.01.14

01. Joint account notifications

15

CX Guideline
MAY

Data holders should refer to disclosure options using plain language. A description of the disclosure option should be provided where possible. These artefacts use 'single consent' to represent pre-approval disclosure option, 'joint consent' to represent co-approval disclosure option, and 'stop all sharing from this account' or 'data sharing disabled' to represent a non-disclosure option.

5CM5.01.15

01. Joint account notifications

16

CX Guideline
MAY

Data holders should provide information about the ADR to relevant account holders. This should include the ADR's name, accreditation number and a link to the their specific page on www.cdr.gov.au/find-a-provider for accreditation verification purposes.

CX Research: 2019 Phase 2, Stream 1 report; 2020 Phase 3, Round 3 report

5CM5.01.16

01. Joint account notifications

17

CX Guideline
MAY

Where an alternative notification schedule is provided as per CDR Rule 4A.14(3), this notification may be omitted at the consumer's request.

CDR Rule 4A.14(3)

5CM5.01.17

01. Joint account notifications

18

CX Guideline
MAY

Community consultation suggested that identifying the specific account holder may raise privacy concerns in some instances. Data holders may identify the specific account holder in relation to the relevant rules requirement, but may also deem it necessary to omit these details in certain scenarios in accordance with CDR Rule 4A.15.

CDR Rule 4A.15

5CM5.01.18

01. Joint account notifications

19

CX Guideline
MAY

Data recipients should educate consumers about data sharing with the CDR, which may include references to the CDR protections. CX research has found that including this information increases familiarity, trustworthiness, propensity to consent, and increase the chances of adoption and successful completion.

5CM5.01.19

01. Joint account notifications

20

CX Guideline
MAY

Data holders should inform the consumer when a notification schedule change only applies for authorisation withdrawal/expiry and approval withdrawal, and not a change to the non-disclosure option.

5CM5.01.20

01. Joint account notifications

21

CX Guideline
MAY

Data holders can refer to accounts using recognised nicknames, icons, account numbers, and account type. They can also include information on other elements the account may refer to such as any related plans, services, properties, numbers, and products.

5CM5.01.21

01. Joint account notifications
Data Standards Body | CX Guidelines

CX Guidelines

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Keep in touch

DSB Newsletter

Website use

Accessibility Statement

Copyright

Privacy

Disclaimer

In the spirit of reconciliation, the Data Standards Body acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples.