Logo
  • Overview
  • Consent
  • Authenticate
  • Authorise
  • Consent Management
  • Notifications
Consumer Experience (CX) Guidelines

CX Guidelines

Read first CX Checklist attributes ◦ Area refers to the stage in the consumer journey, such as Pre-consent, Consent, Authenticate, Authorise, or Consent Management. ◦ Focus area refers to a specific theme in each stage (e.g. 01. User Identifier). ◦ Checklist ref contains a unique reference number for the item. ▪ The first values refer to the Area (e.g. 0DL.xx.xx for data language; 2AU.xx.xx for authentication). ▪ The second set values refer to the Focus area (e.g. xxx.01.xx). ▪ The last values refer to the annotation number used on the wireframe, where available (e.g. xxx.xx.02; wireframes are linked to in the Example column). ◦ Type refers to the source of the statement: Rules, Standards and Guidelines. ◦ Participant refers to the relevant CDR Participant for the item. ◦ Requirement level refers to the level of obligation. For the data standards, the key words MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY are to be interpreted as described in RFC2119. CX Guidelines provide optional examples and recommendations; as such, a MAY is used to denote a CX Guideline for the purposes of this checklist regardless of the language used in the guideline statement. ◦ Statement refers to the relevant requirement or recommendation as articulated in the rules, standards, or guidelines. ◦ References points to the requirement itself, or its location; typically a rule, standard, or research. ◦ Example links to the relevant artefact, such as the CX Guideline page, which includes wireframes of example implementations, or a table in the case of data language standards. ◦ Version introduced refers to the version of the data standards that was current when the item was introduced to the CX Guidelines, starting from version 1.4.0. Items noted as introduced in 1.4.0 or earlier are requirements that exist in v1.4.0 of the CX Guidelines (PDF). ◦ Date introduced refers to the specific date the item was introduced to the CX Checklist, using August 2020 as a starting point (when v1.4.0 was introduced). The date will typically be the date of the version release, but some new items may not constitute a standards change (e.g. a revised wireframe or rules change) and as such may not align with standards versioning. ◦ Date modified refers to when an existing CX Checklist entry was updated, which is not necessarily the date the corresponding requirement (Rule, Standard or Guideline) was changed. ◦ Status refers to whether the item is active or has been retired from the CX Guidelines. An 'active' item is applicable and current. A 'retired' item may be labelled as such because it no longer applies, has been merged with another item, or has been removed from the CX Guidelines. A 'retired' item may still be a requirement. These statuses are used in the live CX Checklist and CSV to highlight changes between versions of the CX Guidelines.
Wireframe ref
Type
Requirement level
Statement
Reference
Checklist ref
Focus area

02

CDR Rule
MUST NOT

(3) An accredited person must not ask for a consent: (a) that is not in a category of consents; or (b) subject to subrule (4), for using the CDR data, including by aggregating the data, for the purpose of: (i) identifying; or (ii) compiling insights in relation to; or (iii) building a profile in relation to; any identifiable person who is not the CDR consumer who made the consumer data request. (4) Paragraph (3)(b) does not apply in relation to a person whose identity is readily apparent from the CDR data, if the accredited person is seeking consent to: (a) derive, from that CDR data, CDR data about that person’s interactions with the CDR consumer; and (b) use that derived CDR data in order to provide the requested goods or services.

CDR Rule 4.12(3), (4)

1CO1.00.02

00. AP disclosure consent - general

03

CDR Rule
MUST

A request by an accredited person for a CDR consumer to give or amend a consent: (a) must comply with any relevant data standards; and (b) having regard to any consumer experience guidelines made by the Data Standards Body—must be reasonably easy to understand, including by use of plain concise language and, where appropriate, visual aids;

CDR Rule 4.10(a)–(b)

1CO1.00.03

00. AP disclosure consent - general

04

CDR Rule
MUST NOT

A request by an accredited person for a CDR consumer to give or amend a consent: (c) must not include or refer to the accredited person’s CDR policy or other documents in a way that reduces understandability; and (d) must not be combined with other requests except for a consent under these rules (other than a request for direct marketing or de-identification consent).

CDR Rule 4.10(c)–(d)

1CO1.00.04

00. AP disclosure consent - general

05

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (a) its name; (b) its accreditation number;

CDR Rule 4.11(3)(a), (b)

1CO1.00.05

00. AP disclosure consent - general

06

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (ba) in the case of a disclosure consent―either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the persons to whom the CDR data may be disclosed; or (ii) seek the CDR consumer’s agreement to the persons (as presented to the CDR consumer) to whom the CDR data may be disclosed;

CDR Rule 4.11(1)(ba)

1CO1.00.06

00. AP disclosure consent - general

07

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must:  (b) in relation to the period of the collection consent, use consent, or disclosure consent (as appropriate)—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the period of consent; or (ii) seek the CDR consumer’s agreement to the period of consent (as presented to the CDR consumer) to which the consent will apply; where the period of consent is either: (iii) a single occasion; or (iv) a specified period of time; Note 2: For paragraph (b), the specified period may not be more than 12 months (or 7 years for certain consents by a CDR business consumer): see subrule 4.12(1). After the end of the period, redundant data would need to be dealt with in accordance with subsection 56EO(2) of the Act (privacy safeguard 12) and rules 7.12 and 7.13.

CDR Rule 4.11(1)(b), (Note 2) | CX Research 4, 5

1CO1.00.07

00. AP disclosure consent - general

08

CDR Rule
MUST NOT

(1) Subject to subrule (1A), an accredited person must not specify a period of time for the purposes of paragraph 4.11(1)(b) that is more than 12 months.

CDR Rule 4.12(1) | CX Research 4, 5

1CO1.00.08

00. AP disclosure consent - general

09

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (a) in the case of a collection consent or a disclosure consent—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the particular types of CDR data to which the consent will apply; or (ii) seek the CDR consumer’s agreement to the particular types of CDR data (as presented to the CDR consumer) to which the consent will apply;

CDR Rule 4.11(1)(a)

1CO1.01.09

01. AP disclosing unmodified data

10

CDR Rule
MUST

(1) The Data Standards Chair must make one or more data standards about each of the following: (d) the types of CDR data and descriptions of those types, to be used by CDR participants in making and responding to requests;

CDR Rule 8.11(1)(d)

1CO1.01.10

01. AP disclosing unmodified data

11

CDR Rule
MUST NOT

(2) The accredited person must not request direct marketing consents or de-identification consents by means of pre-selected options for the purposes of subrule (1). 

CDR Rule 4.11(2)

1CO1.01.11

01. AP disclosing unmodified data

13

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (g) a statement that, at any time, the consent can be withdrawn;

CDR Rule 4.11(3)(g) | CX Research 7, 32

1CO1.00.13

00. AP disclosure consent - general

16

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (h) the following information about redundant data: (i) a statement, in accordance with rule 4.17, regarding the accredited person’s intended treatment of redundant data;

CDR Rule 4.11(3)(h)(i)

1CO1.00.16

00. AP disclosure consent - general

17

CDR Rule
MUST

(1) For subparagraph 4.11(3)(h)(i), the accredited person must state whether they have a general policy, when collected CDR data becomes redundant data, of: (a) deleting the redundant data; or (b) de-identifying the redundant data; or (c) deciding, when the CDR data becomes redundant data, whether to delete it or de-identify it.

CDR Rule 4.17(1) | CX Research 18

1CO1.00.17

00. AP disclosure consent - general

19

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (c) seek the CDR consumer’s express consent to the matters referred to in paragraphs (a), (aa), (b) and (ba) for each relevant category of consents;

CDR Rule 4.11(1)(c)

1CO1.00.19

00. AP disclosure consent - general

20

CDR Rule
MUST

An accredited person must give the CDR consumer a notice that complies with the data standards as soon as practicable after the CDR consumer: (a) gives the accredited person a collection consent, use consent or disclosure consent;

CDR Rule 4.18(a)

1CO1.00.20

00. AP disclosure consent - general

24

CX Standard
MUST

Data Recipients and Data Holders MUST use data language standards to describe data clusters and permissions in consumer-facing interactions. See the Banking and Non-Bank Lending Language section for language to be used when requesting banking and non-bank lending data; and the Energy Language section for language to be used when requesting energy data. Data language standards MUST be used when CDR data is being requested, reviewed, or access to such data is withdrawn. Data Recipients and Data Holders MUST use the appropriate data standards language for business consumers as denoted with an '*' for the relevant data. Data Recipients and Data Holders SHOULD expand on the proposed language where appropriate to communicate further details of what is being shared. Additional details MAY include additional information in context, such as in-line help or tool tips, and/or additional permissions where they may exist. Examples of permission details that MAY be used and provided as in-line help are denoted with an '†' for the relevant data.

Data Language Standards: Common, Data Language Standards: Language to be used

1CO1.01.24

01. AP disclosing unmodified data

25

CX Standard
MUST

If a scenario requires it, Data Holders and Data Recipients MUST merge and amend Basic and Detailed data cluster and permission language to show that Detailed scopes include Basic data. Data Holders and Data Recipients MUST use the alternative language denoted with an '‡' for the relevant scope(s). See the Banking and Non-Bank Lending Language section for banking and non-bank lending data and the Energy Language section for energy data. Example: A Data Recipient presents the Detailed data cluster in a data request to a consumer but does not present the Basic data cluster. The Detailed scope includes Basic data, but this is not apparent to the consumer based on the data cluster language and permissions used for the Detailed scope.

Data Language Standards: Common, Data Language Standards: Detailed scope requests

1CO1.01.25

01. AP disclosing unmodified data

26

CX Standard
MUST

In the course of seeking a consumer’s consent to disclose data as part of a disclosure consent: 1. Data Recipients MUST specify which CDR Participant(s) they collected the associated CDR data from. 2. Data Recipients SHOULD specify the sector(s) the data was collected from or associated with. Note: • Point (1) only requires the Data Recipient to refer to the CDR Participant(s) immediately preceding them in the disclosure chain, which may not always include a consumer’s Data Holder(s). • This standard is proposed to apply to all data to be disclosed by a Data Recipient, including unmodified, aggregated, derived, and transformed CDR data. • Where applicable, the existing data language standards apply to descriptions of CDR data that have not been modified.

Consent Standards, Disclosure consent: Collection source

1CO1.01.26

01. AP disclosing unmodified data

28

CX Guideline
MAY

Data recipients should also include a link to their specific page on www.cdr.gov.au/find-a-provider for accreditation verification purposes.

CX Research: 2019 Phase 2, Stream 1 report; 2020 Phase 3, Round 3 report

1CO1.00.28

00. AP disclosure consent - general

29

CX Guideline
MAY

Data recipients should show the accredited person’s accreditation number to facilitate consumer trust.

CX Research: 2019 Phase 2, Stream 1 report; 2020 Phase 3, Round 3 report

1CO1.00.29

00. AP disclosure consent - general

30

CX Guideline
MAY

Data recipients should provide a link to their CDR policy.

1CO1.00.30

00. AP disclosure consent - general

31

CX Guideline
MAY

Data recipients should make the consent process as easy to understand as possible. Data recipients should nudge consumers to be more privacy conscious and should use appropriate interventions to mitigate cognitive overload, facilitate comprehension, and provide transparency and consumer control. This can be done in a variety of ways, including through the use of design patterns like progressive disclosure, micro and/or descriptive copy, and with the use of microinteractions.

CX Research 8, 19

1CO1.01.31

01. AP disclosing unmodified data

32

CX Guideline
MAY

Data recipients should encourage consumers to check the accredited person’s data handling policies before consenting to have their data disclosed.

1CO1.00.32

00. AP disclosure consent - general

35

CX Guideline
MAY

CDR Representatives seeking an AP disclosure consent from a CDR consumer should refer to CDR Rule 4.3B(2) and Division 4.3A of the CDR Rules.

CDR Rules 4.3B(2), Division 4.3A

1CO1.00.35

00. AP disclosure consent - general

36

CDR Rule
MUST

(2A) The accredited person may also ask a CDR consumer to give a disclosure consent in relation to CDR data, either: (b) after the CDR consumer has given a collection consent requested under subrule (2) in relation to the CDR data whether or not the CDR data has yet been collected. Note 1: Requests for collection consent, use consent and disclosure consent may be bundled together (see subrules 4.3(2) and (2A). Note 2: The CDR data may be disclosed only in accordance with the data minimisation principle: see rule 1.8.

CDR Rule 4.3(2A)(b), (Note 1), (Note 2)

1CO1.00.36

00. AP disclosure consent - general

37

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (c) in the case of a collection consent, use consent or disclosure consent—information about how the collection, use or disclosure indicated in a manner consistent with the requirements set out in subrule (1) complies with the data minimisation principle, including: (ii) in the case of a use consent or disclosure consent—an explanation of why that use or disclosure does not go beyond what is reasonably needed; in order to provide the requested goods or services to the CDR consumer, or to effect the permitted uses or disclosures consented to;

CDR Rule 4.11(3)(c)(ii)

1CO1.00.37

00. AP disclosure consent - general

38

CDR Rule
MUST

Rule 4.18 of the principal rules, as in force immediately before the commencement of the amending rules, continues to apply, on and after that commencement, to an accredited person until the coming into effect of data standards made for the purposes of paragraph 8.11(1)(fa) of the principal rules in relation to rule 4.18.

Part 50—Transitional provisions, CDR Rule 503, Competition and Consumer (Consumer Data Right) Amendment (2024 Measures No. 1) Rules 2024

1CO1.00.38

00. AP disclosure consent - general

39

CX Standard
MUST

Effective from 14 July 2025: A CDR receipt provided by a data recipient MUST be given in writing otherwise than through the consumer dashboard.

Notification Standards, CDR Receipts: Delivery

1CO1.00.39

00. AP disclosure consent - general

40

CX Guideline
MAY

When data is requested and accessed, language used to describe the data must be described in accordance with the relevant CX standards; • ‘Data Language Standards: Language to be used’ and ‘Data Language Standards: Detailed scope requests’ applies when describing unmodified data from data holder(s). • ‘Consent Standards, Disclosure consent: Collection source’ applies to any data collected, but can be stated once where the collection source is the same for all data. • ‘Consent Standards, Disclosure Consent: Descriptions of Data to be Collected and Disclosed’ applies when describing any dataset. 

Data Language Standards: Common | Consent Standards

1CO1.00.40

00. AP disclosure consent - general

41

CX Guideline
MAY

The CX Standards for CDR Receipts take effect on 14 July 2025. The existing requirements regarding CDR receipts will continue to apply until the relevant data standards are made and in effect, as per the transitional provision outlined in CDR Rule 503 (and 506 for CDR representatives). Data recipients should refer to the CDR Rules as they were in effect from 22 July 2023 to 11 November 2024 for details of their obligations with regards to CDR receipts until this date.

CDR Rules 4.18 and 503; 4.20O and 506 | Notification Standards, CDR Receipts

1CO1.00.41

00. AP disclosure consent - general
Data Standards Body | CX Guidelines

CX Guidelines

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Keep in touch

DSB Newsletter

Website use

Accessibility Statement

Copyright

Privacy

Disclaimer

In the spirit of reconciliation, the Data Standards Body acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples.