Logo
  • Overview
  • Consent
  • Authenticate
  • Authorise
  • Consent Management
  • Notifications
Data Standards Body | CX Guidelines

CX Guidelines

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Keep in touch

DSB Newsletter

Website use

Accessibility Statement

Copyright

Privacy

Disclaimer

In the spirit of reconciliation, the Data Standards Body acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples.

Consumer Experience (CX) Guidelines
/
Consent
/
Disclosure consents
/
Business consumer disclosure consents

Business consumer disclosure consents

These guidelines provide examples for how to implement business consumer disclosure consents.
‣
On this page
  • Overview
  • Wireframes and guidelines
  • Detached flow
  • Bundled CDR Consents
  • Download open source asset
  • About this page
  • References
  • Last updated

Overview

The object statement in CDR rule 4.9 provides a strong foundation for giving and amending CDR consents.

‣
Object statement

The elements of the object statement can be described as follows:

  • Voluntary: Consumers must have a genuine choice, with consent being informed, time-limited, and easily withdrawn.
  • Express: Consent must be actively given, not implied.
  • Informed: Consumers must understand the implications of providing consent. The currency of consent is maintained through ongoing engagement, such as appropriate notifications and re-consents.
  • Specific as to purpose: Consent should be for a clear, targeted purpose, not broad or ambiguous use.
  • Time limited: Consent is being requested in relation to a specific and finite period, and extendable only with consumer consent.
  • Easily withdrawn: Consumers must be able to stop access easily.
A high level example of the potential relationship between the initial collect and use consent between the data recipient and a data holder, and a business consumer disclosure consent.
A high level example of the potential relationship between the initial collect and use consent between the data recipient and a data holder, and a business consumer disclosure consent.

Business consumer disclosure consents enable businesses to consent to accredited data recipients sharing their CDR data with software products or specified persons who are not accredited, like bookkeepers, consultants and other advisers who are not classified as trusted advisers under the current CDR Rules.

In accordance with CDR Rule 1.10A(9)–(14), the accredited data recipient must:

  • take reasonable steps to confirm that the consumer is a CDR business consumer;
  • invite a consumer to make a business consumer statement, certifying that the consent is given in a business capacity;
  • not make the giving of a business consumer disclosure consent, or business consumer statement a condition for supply of the goods or services requested, unless the only service that is requested is for data collected and disclosed to a specified person.

Under CDR Rule 1.10AA(1)(a), CDR representatives cannot deal with consumers in their capacity as a CDR business consumer.

Wireframes and guidelines

icon

Note: The wireframes shown are examples of how to implement key rules, standards, and guidelines. Use the on-screen functions to adjust zoom level or expand the wireframes to be viewed at full screen.

Detached flow

The following wireframes show a basic example of a business consumer disclosure consent. In this example:

  • the collection/use consent has already been separately established, allowing a disclosure consent to be requested in a separate consent flow;
  • the consumer has selected the specified person during consent.
‣
See key requirements and guidelines
Wireframe ref
Type
Requirement level
Statement
Reference
Checklist ref
Focus area

01

CDR Rule
MUST

(2A) The accredited person may also ask a CDR consumer to give a disclosure consent in relation to CDR data, either: (b) after the CDR consumer has given a collection consent requested under subrule (2) in relation to the CDR data whether or not the CDR data has yet been collected. Note 1: Requests for collection consent, use consent and disclosure consent may be bundled together (see subrules 4.3(2) and (2A). Note 2: The CDR data may be disclosed only in accordance with the data minimisation principle: see rule 1.8.

CDR Rule 4.3(2A)(b), (Note 1), (Note 2)

1CO5.00.01

00. Business consumer disclosure consent - general

02

CDR Rule
MUST

(11) For these rules, a business consumer disclosure consent in relation to particular CDR data of a CDR business consumer held by an accredited data recipient is a disclosure consent given by the CDR business consumer under these rules that: (a) authorises the accredited data recipient to disclose the CDR data to a specified person; and (b) includes a business consumer statement.

CDR Rule 1.10A(11)

1CO5.00.02

00. Business consumer disclosure consent - general

03

CDR Rule
MUST NOT

(12) An accredited person must not make: (c) the specification of a particular person for the purposes of paragraph (11)(a); a condition for supply of the goods or services requested by the CDR business consumer.

CDR Rule 1.10A(12)(c)

1CO5.00.03

00. Business consumer disclosure consent - general

04

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must:(ba) in the case of a disclosure consent―either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the persons to whom the CDR data may be disclosed; or (ii) seek the CDR consumer’s agreement to the persons (as presented to the CDR consumer) to whom the CDR data may be disclosed;

CDR Rule 4.11(1)(ba)

1CO5.00.04

00. Business consumer disclosure consent - general

05

CDR Rule
MUST

(9) For these rules, a CDR consumer is taken to be a CDR business consumer in relation to a consumer data request to be made by an accredited person if the accredited person has taken reasonable steps to confirm that: (a) the CDR consumer is not an individual; or (b) the CDR consumer has an active ABN.

CDR Rule 1.10A(9)

1CO5.00.05

00. Business consumer disclosure consent - general

06

CDR Rule
MUST

(2) An accredited data recipient must keep and maintain records that record and explain the following: (eg) any steps taken for the purposes of subrule 1.10A(9) to confirm that a CDR consumer is a CDR business consumer;

CDR Rule 9.3(2)(eg)

1CO5.00.06

00. Business consumer disclosure consent - general

07

CDR Rule
MUST

(10) For these rules, a business consumer statement is a statement made by a CDR business consumer that: (a) is given in relation to a consent in one of the following categories: (i) use consents relating to the goods or services requested by the CDR business consumer; (ii) TA disclosure consents; (iii) insight disclosure consents; (iv) business consumer disclosure consents; and (b) certifies that the consent is given for the purpose of enabling the accredited person to provide goods or services to the CDR business consumer in its capacity as a business (and not as an individual). Note: Only an accredited person is able to deal with a CDR consumer in the CDR consumer’s capacity as a CDR business consumer, and is hence able to invite a CDR consumer to provide a business consumer statement.

CDR Rule 1.10A(10), (Note)

1CO5.00.07

00. Business consumer disclosure consent - general

08

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (bb) where the accredited person proposes, or is offering, to deal with a person in their capacity as a CDR business consumer in relation to a consent of a kind mentioned in paragraph 1.10A(10)(a)―invite the CDR business consumer to provide the business consumer statement

CDR Rule 4.11(1)(bb)

1CO5.00.08

00. Business consumer disclosure consent - general

09

CDR Rule
MUST NOT

(12) An accredited person must not make: (b) the giving of a business consumer statement; a condition for supply of the goods or services requested by the CDR business consumer.

CDR Rule 1.10A(12)(b)

1CO5.00.09

00. Business consumer disclosure consent - general

10

CDR Rule
MUST

(13) To avoid doubt, paragraphs (12)(a) and (b) do not apply where the only good or service that is requested by the CDR business consumer is for CDR data to be collected from a data holder and provided to a specified person.

CDR Rule 1.10A(13)

1CO5.00.10

00. Business consumer disclosure consent - general

11

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (b) in relation to the period of the collection consent, use consent, or disclosure consent (as appropriate)—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the period of consent; or (ii) seek the CDR consumer’s agreement to the period of consent (as presented to the CDR consumer) to which the consent will apply; where the period of consent is either: (iii) a single occasion; or (iv) a specified period of time; and Note 2: For paragraph (b), the specified period may not be more than 12 months (or 7 years for certain consents by a CDR business consumer): see subrule 4.12(1). After the end of the period, redundant data would need to be dealt with in accordance with subsection 56EO(2) of the Act (privacy safeguard 12) and rules 7.12 and 7.13.

CDR Rule 4.11(1)(b), (Note 2)

1CO5.00.11

00. Business consumer disclosure consent - general

12

CDR Rule
MUST NOT

(1) Subject to subrule (1A), an accredited person must not specify a period of time for the purposes of paragraph 4.11(1)(b) that is more than 12 months.

CDR Rule 4.12(1)

1CO5.00.12

00. Business consumer disclosure consent - general

13

CDR Rule
MUST

(1A) In the case of a consent given by a CDR business consumer that includes a business consumer statement, an accredited person must: (a) not specify a period of time that is more than 7 years; and (b) if specifying a period of time of more than 12 months, give the CDR business consumer the option of choosing a period for the consent of 12 months or less.

CDR Rule 4.12(1A)

1CO5.00.13

00. Business consumer disclosure consent - general

14

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must:(a) in the case of a collection consent or a disclosure consent—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the particular types of CDR data to which the consent will apply; or (ii) seek the CDR consumer’s agreement to the particular types of CDR data (as presented to the CDR consumer) to which the consent will apply;

CDR Rule 4.11(1)(a)

1CO5.00.14

00. Business consumer disclosure consent - general

15

CDR Rule
MUST

An accredited person must give the CDR consumer a notice that complies with the data standards as soon as practicable after the CDR consumer: (a) gives the accredited person a collection consent, use consent or disclosure consent;

CDR Rule 4.18(a)

1CO5.00.15

00. Business consumer disclosure consent - general

18

CX Standard
MUST

Data recipients MUST use plain and concise language when inviting a consumer to give a business consumer statement.

Consent Standards, Business consumer statement: Content

1CO5.00.18

00. Business consumer disclosure consent - general

19

CX Standard
MUST

When seeking a business consumer statement, data recipients MUST invite the business consumer to give the business consumer statement in a manner that is explicit, express, and through an active selection or declaration. The giving of a business consumer statement MUST be clearly separated from any other interaction or information provided to the consumer and MUST NOT be implied or bundled with any other permission.

Consent Standards, Business consumer statement: Method

1CO5.00.19

00. Business consumer disclosure consent - general

20

CX Standard
MUST

Data Recipients and Data Holders MUST use data language standards to describe data clusters and permissions in consumer-facing interactions. See the Banking and Non-Bank Lending Language section for language to be used when requesting banking and non-bank lending data; and the Energy Language section for language to be used when requesting energy data. Data language standards MUST be used when CDR data is being requested, reviewed, or access to such data is withdrawn. Data Recipients and Data Holders MUST use the appropriate data standards language for business consumers as denoted with an '*' for the relevant data. Data Recipients and Data Holders SHOULD expand on the proposed language where appropriate to communicate further details of what is being shared. Additional details MAY include additional information in context, such as in-line help or tool tips, and/or additional permissions where they may exist. Examples of permission details that MAY be used and provided as in-line help are denoted with an '†' for the relevant data.

Data Language Standards: Common, Data Language Standards: Language to be used

1CO5.00.20

00. Business consumer disclosure consent - general

21

CX Standard
MUST

If a scenario requires it, Data Holders and Data Recipients MUST merge and amend Basic and Detailed data cluster and permission language to show that Detailed scopes include Basic data. Data Holders and Data Recipients MUST use the alternative language denoted with an '‡' for the relevant scope(s). See the Banking and Non-Bank Lending Language section for banking and non-bank lending data and the Energy Language section for energy data. Example: A Data Recipient presents the Detailed data cluster in a data request to a consumer but does not present the Basic data cluster. The Detailed scope includes Basic data, but this is not apparent to the consumer based on the data cluster language and permissions used for the Detailed scope.

Data Language Standards: Common, Data Language Standards: Detailed scope requests

1CO5.00.21

00. Business consumer disclosure consent - general

22

CX Standard
MUST

In the course of seeking a consumer’s consent to disclose data as part of a disclosure consent: 1. Data Recipients MUST specify which CDR Participant(s) they collected the associated CDR data from. 2. Data Recipients SHOULD specify the sector(s) the data was collected from or associated with. Note: • Point (1) only requires the Data Recipient to refer to the CDR Participant(s) immediately preceding them in the disclosure chain, which may not always include a consumer’s Data Holder(s). • This standard is proposed to apply to all data to be disclosed by a Data Recipient, including unmodified, aggregated, derived, and transformed CDR data. • Where applicable, the existing data language standards apply to descriptions of CDR data that have not been modified.

Consent Standards, Disclosure consent: Collection source

1CO5.00.22

00. Business consumer disclosure consent - general

23

CX Standard
MUST

Data recipients MUST state that data disclosed to a non-accredited person will not be regulated as part of the Consumer Data Right. This information SHOULD be immediately viewable by the consumer without further interaction. Data recipients MAY include a plain and concise explanation of what this means, which MAY include information on the Consumer Data Right, and MAY include a link to the Office of the Australian Information Commissioner guidance on the Consumer Data Right.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: CDR protections

1CO5.00.23

00. Business consumer disclosure consent - general

24

CX Standard
MUST

Data recipients MUST provide plain and concise information on dispute resolution and making a complaint. This SHOULD reflect the process and information contained in the data recipient’s CDR policy related to complaints. This MAY also include a link to the accredited data recipient’s CDR policy.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Complaints

1CO5.00.24

00. Business consumer disclosure consent - general

25

CX Standard
MUST

Data recipients MUST advise the consumer to review how the non-accredited person will handle their data.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Review

1CO5.00.25

00. Business consumer disclosure consent - general

26

CX Standard
MAY

If available, data recipients MAY include a link to any relevant data handling policies of the non-accredited person, such as their Privacy Policy.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Data handling

1CO5.00.26

00. Business consumer disclosure consent - general

27

CX Standard
MUST

Data recipients MUST provide the information contained in the disclosure notification otherwise than in the consent flow. This SHOULD be contained in the consumer’s CDR Receipt. This SHOULD also be accessible in the consumer dashboard as part of the data sharing arrangement details. Note 1: The information to be included is limited to the following standards: CDR Protections; Review; Data Handling; Complaints; and Insight Records. The scope of information to include will depend on the accredited person’s specific implementation. Note 2: This standard does not alter any existing rules obligations for CDR receipts or dashboards.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Notification record

1CO5.00.27

00. Business consumer disclosure consent - general

28

CX Guideline
MAY

Data recipients may invite a consumer to give a use consent to confirm whether they are a business consumer, per the requirements of CDR Rule 1.10A(9). This could be requested in conjunction with a collection consent, or could be requested as a detached use for already collected data.

CDR Rule 1.10A(9)

1CO5.00.28

00. Business consumer disclosure consent - general

29

CX Guideline
MAY

Data recipients should only request a business consumer statement if they have verified the consumer is a business consumer — per CDR Rule 1.10(9) — and reasonably expect them to be intending to use the service for business purposes. Appropriate pre-consent and onboarding experiences can assist with funnelling consumers towards the most appropriate consent flow for their needs. This can reduce cognitive load for non-business consumers, and prevent consumers from inadvertently providing a business consumer statement.

CDR Rule 1.10(9)

1CO5.00.29

00. Business consumer disclosure consent - general

32

CX Guideline
MAY

Inline with CDR Rule 1.10A(9), when verifying the consumer is not an individual or has an active ABN, data recipients should be satisfied that the evidence given — such as the ABN — is current and relates to the consumer.

CDR Rule 1.10A(9)

1CO5.00.32

00. Business consumer disclosure consent - general

33

CX Guideline
MAY

In accordance with CDR Rule 4.11(1)(bb), data recipients must invite a business consumer to give a business consumer statement in the consent flow. This invitation should be presented upfront. Doing so can help data recipients determine the appropriate consent duration and customer data language standards to surface, and whether a business consumer disclosure consent can be requested.

CDR Rule 4.11(1)(bb)

1CO5.00.33

00. Business consumer disclosure consent - general

34

CX Guideline
MAY

Data recipients must only present business consumers with a pre-selected duration of more than 12 months where the service reasonably requires this and in compliance with the data minimisation principle, CDR Rule 1.8.

CDR Rule 1.8

1CO5.00.34

00. Business consumer disclosure consent - general

35

CX Guideline
MAY

Where a data recipient presents a duration over 12 months for a consent that includes a business consumer statement, they must give the consumer at least one option of 12 months or less, to meet CDR Rule 4.12(1A)(b). For example, if a data recipient presents a 3 year duration, they might offer a 12 month option, a 6 month option, or both, but at least one must be offered. Data recipients are not required to allow the consumer to choose an alternative duration where durations of 12 months or less are proposed. However, data recipients may voluntarily provide this choice. When presenting duration options, data recipients should present consumers with a limited selection of duration options to reduce cognitive load. The options presented should represent the most common and/or most appropriate durations for the service being offered and be in compliance with the data minimisation principle.

CDR Rule 4.12(1A)(b) | Nielsen Norman Group: 10 Usability Heuristics for User Interface Design (Error prevention)

1CO5.00.35

00. Business consumer disclosure consent - general

36

CX Guideline
MAY

Data recipients are encouraged to provide links to the non-accredited person’s data handling information for the consumer to review. CX research and consultation suggested that accurate information on data handling provided by the non-accredited person would increase trustworthiness and consumer comfort.

CX Research: 2021 Disclosure Consent report

1CO5.00.36

00. Business consumer disclosure consent - general

37

CX Guideline
MAY

If the non-accredited person does not have a Privacy Policy, data recipients are encouraged to provide the consumer with other details; • to contact the non-accredited person; or • to review up-to-date information on the non-accredited person's data handling policies.

CX Research: 2021 Disclosure Consent report

1CO5.00.37

00. Business consumer disclosure consent - general

38

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (c) in the case of a collection consent, use consent or disclosure consent—information about how the collection, use or disclosure indicated in a manner consistent with the requirements set out in subrule (1) complies with the data minimisation principle, including: (ii) in the case of a use consent or disclosure consent—an explanation of why that use or disclosure does not go beyond what is reasonably needed; in order to provide the requested goods or services to the CDR consumer, or to effect the permitted uses or disclosures consented to;

CDR Rule 4.11(3)(c)(ii)

1CO5.00.38

00. Business consumer disclosure consent - general

39

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (c) seek the CDR consumer’s express consent to the matters referred to in paragraphs (a), (aa), (b) and (ba) for each relevant category of consents;

CDR Rule 4.11(1)(c)

1CO5.00.39

00. Business consumer disclosure consent - general

40

CDR Rule
MUST

Rule 4.18 of the principal rules, as in force immediately before the commencement of the amending rules, continues to apply, on and after that commencement, to an accredited person until the coming into effect of data standards made for the purposes of paragraph 8.11(1)(fa) of the principal rules in relation to rule 4.18.

CDR Rule 503

1CO5.00.40

00. Business consumer disclosure consent - general

41

CX Standard
MUST

Effective from 14 July 2025: A CDR receipt provided by a data recipient MUST be given in writing otherwise than through the consumer dashboard.

Notification Standards, CDR Receipts: Delivery

1CO5.00.41

00. Business consumer disclosure consent - general

42

CX Guideline
MAY

The rules do not allow an individual without an active ABN to be treated as a CDR business consumer.

ACCC CDR business consumers - Fact sheet

1CO5.00.42

00. Business consumer disclosure consent - general

43

CX Guideline
MAY

Data recipients should use their discretion to determine whether a step to select a non-Accredited Person is required for their service. For example, the selection step may be necessary where the data recipient offers a range persons to whom the consumer can disclose. By contrast, the selection step may not be necessary where the consumer has a pre-existing relationship with a non-Accredited Person and the data recipient can reasonably assume that the consumer is engaging their service to disclose their data to this non-AP.

CDR Rule 4.11(1)(ba)

1CO5.00.43

00. Business consumer disclosure consent - general

44

CX Guideline
MAY

Data recipients should make the consent process as easy to understand as possible. Data recipients should nudge consumers to be more privacy conscious and should use appropriate interventions to mitigate cognitive overload, facilitate comprehension, and provide transparency and consumer control. This can be done in a variety of ways, including through the use of design patterns like progressive disclosure, micro and/or descriptive copy, and with the use of microinteractions.

CX Research 8, 19

1CO5.00.44

00. Business consumer disclosure consent - general

45

CX Guideline
MAY

When data is requested and accessed, language used to describe the data must be described in accordance with the relevant CX standards; • ‘Data Language Standards: Language to be used’ and ‘Data Language Standards: Detailed scope requests’ applies when describing unmodified data from data holder(s). • ‘Consent Standards, Disclosure consent: Collection source’ applies to any data collected, but can be stated once where the collection source is the same for all data. • ‘Consent Standards, Disclosure Consent: Descriptions of Data to be Collected and Disclosed’ applies when describing any dataset.

Data Language Standards: Common | Consent Standards

1CO5.00.45

00. Business consumer disclosure consent - general

46

CX Guideline
MAY

Data recipients should send CDR receipts via the consumer's preferred delivery channels, other than through the consumer dashboard.

1CO5.00.46

00. Business consumer disclosure consent - general

47

CX Guideline
MAY

The CX Standards for CDR Receipts take effect on 14 July 2025. The existing requirements regarding CDR receipts will continue to apply until the relevant data standards are made and in effect, as per the transitional provision outlined in CDR Rule 503 (and 506 for CDR representatives). Data recipients should refer to the CDR Rules as they were in effect from 22 July 2023 to 11 November 2024 for details of their obligations with regards to CDR receipts until this date.

CDR Rules 4.18 and 503; 4.20O and 506 | Notification Standards, CDR Receipts

1CO5.00.47

00. Business consumer disclosure consent - general
‣
See prototype

Note: Some interactions and screens have been omitted for simplicity.

Bundled CDR Consents

The following wireframes show a basic example of a bundled Collection, Use and Business consumer disclosure consent request by an accredited data recipient. In this example,

  • the data recipient is requesting a collection consent, a use consent, and a disclosure consent in a single consent flow;
  • the accredited data recipient has pre-selected the specified person.

This pattern could, for example, apply when the CDR consumer has a pre-existing relationship with a non-Accredited Person and the data recipient can reasonably assume that the consumer is engaging their service to disclose their data to this specified person. Data recipients should use their discretion to determine whether a step to select the specified person is required for their service. For example, the selection step may be necessary where the data recipient offers a range persons to whom the consumer can disclose.

‣
See key requirements and guidelines
Wireframe ref
Type
Requirement level
Statement
Reference
Checklist ref
Focus area

01

CDR Rule
MUST

(11) For these rules, a business consumer disclosure consent in relation to particular CDR data of a CDR business consumer held by an accredited data recipient is a disclosure consent given by the CDR business consumer under these rules that: (a) authorises the accredited data recipient to disclose the CDR data to a specified person; and (b) includes a business consumer statement.

CDR Rule 1.10A(11)

1CO5.01.01

01. Business consumer disclosure consent - Bundled CDR consents

02

CDR Rule
MUST

(9) For these rules, a CDR consumer is taken to be a CDR business consumer in relation to a consumer data request to be made by an accredited person if the accredited person has taken reasonable steps to confirm that: (a) the CDR consumer is not an individual; or (b) the CDR consumer has an active ABN.

CDR Rule 1.10A(9)

1CO5.01.02

01. Business consumer disclosure consent - Bundled CDR consents

03

CDR Rule
MUST

(2) An accredited data recipient must keep and maintain records that record and explain the following: (eg) any steps taken for the purposes of subrule 1.10A(9) to confirm that a CDR consumer is a CDR business consumer;

CDR Rule 9.3(2)(eg)

1CO5.01.03

01. Business consumer disclosure consent - Bundled CDR consents

04

CDR Rule
MUST

(10) For these rules, a business consumer statement is a statement made by a CDR business consumer that: (a) is given in relation to a consent in one of the following categories:  (i) use consents relating to the goods or services requested by the CDR business consumer;  (ii) TA disclosure consents;  (iii) insight disclosure consents;  (iv) business consumer disclosure consents; and (b) certifies that the consent is given for the purpose of enabling the accredited person to provide goods or services to the CDR business consumer in its capacity as a business (and not as an individual). Note: Only an accredited person is able to deal with a CDR consumer in the CDR consumer’s capacity as a CDR business consumer, and is hence able to invite a CDR consumer to provide a business consumer statement.

CDR Rule 1.10A(10), (Note)

1CO5.01.04

01. Business consumer disclosure consent - Bundled CDR consents

05

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (bb) where the accredited person proposes, or is offering, to deal with a person in their capacity as a CDR business consumer in relation to a consent of a kind mentioned in paragraph 1.10A(10)(a)―invite the CDR business consumer to provide the business consumer statement;

CDR Rule 1.10A(11)

1CO5.01.05

01. Business consumer disclosure consent - Bundled CDR consents

06

CDR Rule
MUST

(12) An accredited person must not make: (b) the giving of a business consumer statement; a condition for supply of the goods or services requested by the CDR business consumer.

CDR Rule 1.10A(12)(b)

1CO5.01.06

01. Business consumer disclosure consent - Bundled CDR consents

07

CDR Rule
MUST

(13) To avoid doubt, paragraphs (12)(a) and (b) do not apply where the only good or service that is requested by the CDR business consumer is for CDR data to be collected from a data holder and provided to a specified person.

CDR Rule 1.10A(13)

1CO5.01.07

01. Business consumer disclosure consent - Bundled CDR consents

08

CDR Rule
MUST

(2A) The accredited person may also ask a CDR consumer to give a disclosure consent in relation to CDR data, either: (a) at the same time the accredited person asks the CDR consumer to give a collection consent under subrule (2) in relation to the CDR data; Note 1: Requests for collection consent, use consent and disclosure consent may be bundled together (see subrules 4.3(2) and (2A). Note 2: The CDR data may be disclosed only in accordance with the data minimisation principle: see rule 1.8.

CDR Rule 4.3(2A)(a), (Note 1), (Note 2)

1CO5.01.08

01. Business consumer disclosure consent - Bundled CDR consents

09

CDR Rule
MUST

(3) An accredited person must not ask for a consent:  (a) that is not in a category of consents; or  (b) subject to subrule (4), for using the CDR data, including by aggregating the data, for the purpose of:  (i) identifying; or  (ii) compiling insights in relation to; or  (iii) building a profile in relation to;  any identifiable person who is not the CDR consumer who made the consumer data request.  (4) Paragraph (3)(b) does not apply in relation to a person whose identity is readily apparent from the CDR data, if the accredited person is seeking consent to:  (a) derive, from that CDR data, CDR data about that person’s interactions with the CDR consumer; and  (b) use that derived CDR data in order to provide the requested goods or services. 

CDR Rule 4.12(3)–(4)

1CO5.01.09

01. Business consumer disclosure consent - Bundled CDR consents

10

CDR Rule
MUST

A request by an accredited person for a CDR consumer to give or amend a consent: (a) must comply with any relevant data standards; and (b) having regard to any consumer experience guidelines made by the Data Standards Body—must be reasonably easy to understand, including by use of plain concise language and, where appropriate, visual aids;

CDR Rule 4.10(a)–(b)

1CO5.01.10

01. Business consumer disclosure consent - Bundled CDR consents

11

CDR Rule
MUST

A request by an accredited person for a CDR consumer to give or amend a consent: (c) must not include or refer to the accredited person’s CDR policy or other documents in a way that reduces understandability; and (d) must not be combined with other requests except for a consent under these rules (other than a request for direct marketing or de-identification consent).

CDR Rule 4.10(c)–(d)

1CO5.01.11

01. Business consumer disclosure consent - Bundled CDR consents

12

CDR Rule
MUST

(2) An accredited person must not ask for a collection consent, use consent or disclosure consent unless the collection, use or disclosure of CDR data in accordance with the consent would comply with the data minimisation principle.

CDR Rule 4.12(2) | OAIC Chapter C: Consent (Data minimisation principle) | CX Research 1, 3

1CO5.01.12

01. Business consumer disclosure consent - Bundled CDR consents

13

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (b) in relation to the period of the collection consent, use consent, or disclosure consent (as appropriate)—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the period of consent; or (ii) seek the CDR consumer’s agreement to the period of consent (as presented to the CDR consumer) to which the consent will apply; where the period of consent is either: (iii) a single occasion; or (iv) a specified period of time; Note 2: For paragraph (b), the specified period may not be more than 12 months (or 7 years for certain consents by a CDR business consumer): see subrule 4.12(1). After the end of the period, redundant data would need to be dealt with in accordance with subsection 56EO(2) of the Act (privacy safeguard 12) and rules 7.12 and 7.13.

CDR Rule 4.11(1)(b), (Note 2) | CX Research 4, 5

1CO5.01.13

01. Business consumer disclosure consent - Bundled CDR consents

14

CDR Rule
MUST

(1) Subject to subrule (1A), an accredited person must not specify a period of time for the purposes of paragraph 4.11(1)(b) that is more than 12 months.

CDR Rule 4.12(1) | CX Research 4, 5

1CO5.01.14

01. Business consumer disclosure consent - Bundled CDR consents

15

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (ba) in the case of a disclosure consent―either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the persons to whom the CDR data may be disclosed; or (ii) seek the CDR consumer’s agreement to the persons (as presented to the CDR consumer) to whom the CDR data may be disclosed;

CDR Rule 4.11(1)(ba)

1CO5.01.15

01. Business consumer disclosure consent - Bundled CDR consents

16

CDR Rule
MUST

(12) An accredited person must not make: (c) the specification of a particular person for the purposes of paragraph (11)(a); a condition for supply of the goods or services requested by the CDR business consumer.

CDR Rule 1.10A(12)(c)

1CO5.01.16

01. Business consumer disclosure consent - Bundled CDR consents

17

CDR Rule
MUST

(10) For these rules, a business consumer statement is a statement made by a CDR business consumer that: (a) is given in relation to a consent in one of the following categories: (i) use consents relating to the goods or services requested by the CDR business consumer; (iv) business consumer disclosure consents;

CDR Rule 1.10A(10)(a)(i),(iv)

1CO5.01.17

01. Business consumer disclosure consent - Bundled CDR consents

18

CDR Rule
MUST

(1A) In the case of a consent given by a CDR business consumer that includes a business consumer statement, an accredited person must: (a) not specify a period of time that is more than 7 years; and (b) if specifying a period of time of more than 12 months, give the CDR business consumer the option of choosing a period for the consent of 12 months or less.

CDR Rule 4.12(1A)

1CO5.01.18

01. Business consumer disclosure consent - Bundled CDR consents

19

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (c) in the case of a collection consent, use consent or disclosure consent—information about how the collection, use or disclosure indicated in a manner consistent with the requirements set out in subrule (1) complies with the data minimisation principle, including: (i) in the case of a collection consent in relation to the provision of requested goods or services—an explanation of why that collection is reasonably needed, and relates to a time period that is no longer than is reasonably needed; in order to provide the requested goods or services to the CDR consumer, or to effect the permitted uses or disclosures consented to;

CDR Rule 4.11(3)(c)(i)

1CO5.01.19

01. Business consumer disclosure consent - Bundled CDR consents

20

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (a) in the case of a collection consent or a disclosure consent—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the particular types of CDR data to which the consent will apply; or (ii) seek the CDR consumer’s agreement to the particular types of CDR data (as presented to the CDR consumer) to which the consent will apply;

CDR Rule 4.11(1)(a)

1CO5.01.20

01. Business consumer disclosure consent - Bundled CDR consents

21

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (aa) in the case of a use consent—either: (i) allow the CDR consumer to actively select or otherwise clearly indicate the specific uses of collected data to which the consent will apply; or (ii) seek the CDR consumer’s agreement to the specific uses of collected data (as presented to the CDR consumer) to which the consent will apply;

CDR Rule 4.11(1)(aa) | CX Research 2, 6

1CO5.01.21

01. Business consumer disclosure consent - Bundled CDR consents

22

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (c) in the case of a collection consent, use consent or disclosure consent—information about how the collection, use or disclosure indicated in a manner consistent with the requirements set out in subrule (1) complies with the data minimisation principle, including: (ii) in the case of a use consent or disclosure consent—an explanation of why that use or disclosure does not go beyond what is reasonably needed; in order to provide the requested goods or services to the CDR consumer, or to effect the permitted uses or disclosures consented to;

CDR Rule 4.11(3)(c)(ii) | OAIC Chapter C: Consent (Data minimisation principle) | CX Research 1, 3

1CO5.01.22

01. Business consumer disclosure consent - Bundled CDR consents

23

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information:  (a) its name;  (b) its accreditation number; 

CDR Rule 4.11(3)(a), (b)

1CO5.01.23

01. Business consumer disclosure consent - Bundled CDR consents

24

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (g) a statement that, at any time, the consent can be withdrawn;

CDR Rule 4.11(3)(g) | CX Research 7, 32

1CO5.01.24

01. Business consumer disclosure consent - Bundled CDR consents

25

CDR Rule
MUST

(3) When asking a CDR consumer to give consent, the accredited person must give the CDR consumer the following information: (h) the following information about redundant data: (i) a statement, in accordance with rule 4.17, regarding the accredited person’s intended treatment of redundant data;

CDR Rule 4.11(3)(h)(i)

1CO5.01.25

01. Business consumer disclosure consent - Bundled CDR consents

26

CDR Rule
MUST

(1) For subparagraph 4.11(3)(h)(i), the accredited person must state whether they have a general policy, when collected CDR data becomes redundant data, of: (a) deleting the redundant data; or (b) de-identifying the redundant data; or (c) deciding, when the CDR data becomes redundant data, whether to delete it or de-identify it.

CDR Rule 4.17(1) | CX Research 18

1CO5.01.26

01. Business consumer disclosure consent - Bundled CDR consents

27

CDR Rule
MUST

(1) When asking a CDR consumer to give a consent, an accredited person must: (c) seek the CDR consumer’s express consent to the matters referred to in paragraphs (a), (aa), (b) and (ba) for each relevant category of consents;

CDR Rule 4.11(1)(c)

1CO5.01.27

01. Business consumer disclosure consent - Bundled CDR consents

28

CDR Rule
MUST

An accredited person must give the CDR consumer a notice that complies with the data standards as soon as practicable after the CDR consumer: (a) gives the accredited person a collection consent, use consent or disclosure consent;

CDR Rule 4.18(a)

1CO5.01.28

01. Business consumer disclosure consent - Bundled CDR consents

29

CDR Rule
MUST

Rule 4.18 of the principal rules, as in force immediately before the commencement of the amending rules, continues to apply, on and after that commencement, to an accredited person until the coming into effect of data standards made for the purposes of paragraph 8.11(1)(fa) of the principal rules in relation to rule 4.18.

CDR Rule 503

1CO5.01.29

01. Business consumer disclosure consent - Bundled CDR consents

30

CX Standard
MUST

Data recipients MUST use plain and concise language when inviting a consumer to give a business consumer statement.

Consent Standards, Business consumer statement: Content

1CO5.01.30

01. Business consumer disclosure consent - Bundled CDR consents

31

CX Standard
MUST

When seeking a business consumer statement, data recipients MUST invite the business consumer to give the business consumer statement in a manner that is explicit, express, and through an active selection or declaration. The giving of a business consumer statement MUST be clearly separated from any other interaction or information provided to the consumer and MUST NOT be implied or bundled with any other permission.

Consent Standards, Business consumer statement: Method

1CO5.01.31

01. Business consumer disclosure consent - Bundled CDR consents

32

CX Standard
MUST

Data Recipients and Data Holders MUST use data language standards to describe data clusters and permissions in consumer-facing interactions. See the Banking and Non-Bank Lending Language section for language to be used when requesting banking and non-bank lending data; and the Energy Language section for language to be used when requesting energy data. Data language standards MUST be used when CDR data is being requested, reviewed, or access to such data is withdrawn. Data Recipients and Data Holders MUST use the appropriate data standards language for business consumers as denoted with an '*' for the relevant data. Data Recipients and Data Holders SHOULD expand on the proposed language where appropriate to communicate further details of what is being shared. Additional details MAY include additional information in context, such as in-line help or tool tips, and/or additional permissions where they may exist. Examples of permission details that MAY be used and provided as in-line help are denoted with an '†' for the relevant data.

Data Language Standards: Common, Data Language Standards: Language to be used

1CO5.01.32

01. Business consumer disclosure consent - Bundled CDR consents

33

CX Standard
MUST

If a scenario requires it, Data Holders and Data Recipients MUST merge and amend Basic and Detailed data cluster and permission language to show that Detailed scopes include Basic data. Data Holders and Data Recipients MUST use the alternative language denoted with an '‡' for the relevant scope(s). See the Banking and Non-Bank Lending Language section for banking and non-bank lending data and the Energy Language section for energy data. Example: A Data Recipient presents the Detailed data cluster in a data request to a consumer but does not present the Basic data cluster. The Detailed scope includes Basic data, but this is not apparent to the consumer based on the data cluster language and permissions used for the Detailed scope.

Data Language Standards: Common, Data Language Standards: Detailed scope requests

1CO5.01.33

01. Business consumer disclosure consent - Bundled CDR consents

34

CX Standard
MUST

In the course of seeking a consumer’s consent to disclose data as part of a disclosure consent: 1. Data Recipients MUST specify which CDR Participant(s) they collected the associated CDR data from. 2. Data Recipients SHOULD specify the sector(s) the data was collected from or associated with. Note: • Point (1) only requires the Data Recipient to refer to the CDR Participant(s) immediately preceding them in the disclosure chain, which may not always include a consumer’s Data Holder(s). • This standard is proposed to apply to all data to be disclosed by a Data Recipient, including unmodified, aggregated, derived, and transformed CDR data. • Where applicable, the existing data language standards apply to descriptions of CDR data that have not been modified.

Consent Standards, Disclosure consent: Collection source

1CO5.01.34

01. Business consumer disclosure consent - Bundled CDR consents

35

CX Standard
MUST

Data recipients MUST state that data disclosed to a non-accredited person will not be regulated as part of the Consumer Data Right. This information SHOULD be immediately viewable by the consumer without further interaction. Data recipients MAY include a plain and concise explanation of what this means, which MAY include information on the Consumer Data Right, and MAY include a link to the Office of the Australian Information Commissioner guidance on the Consumer Data Right.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: CDR protections

1CO5.01.35

01. Business consumer disclosure consent - Bundled CDR consents

36

CX Standard
MUST

Data recipients MUST notify consumers of redirection prior to authentication.

Consent Standards, Consent: Redirection

1CO5.01.36

01. Business consumer disclosure consent - Bundled CDR consents

37

CX Standard
MUST

Data recipients MUST provide plain and concise information on dispute resolution and making a complaint. This SHOULD reflect the process and information contained in the data recipient’s CDR policy related to complaints. This MAY also include a link to the accredited data recipient’s CDR policy.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Complaints

1CO5.01.37

01. Business consumer disclosure consent - Bundled CDR consents

38

CX Standard
MUST

Data recipients MUST advise the consumer to review how the non-accredited person will handle their data.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Review

1CO5.01.38

01. Business consumer disclosure consent - Bundled CDR consents

39

CX Standard
MAY

If available, data recipients MAY include a link to any relevant data handling policies of the non-accredited person, such as their Privacy Policy.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Data handling

1CO5.01.39

01. Business consumer disclosure consent - Bundled CDR consents

40

CX Standard
MUST

Effective from 14 July 2025: A CDR receipt provided by a data recipient MUST be given in writing otherwise than through the consumer dashboard.

Notification Standards, CDR Receipts: Delivery

1CO5.01.40

01. Business consumer disclosure consent - Bundled CDR consents

41

CX Standard
MUST

Data recipients MUST provide the information contained in the disclosure notification otherwise than in the consent flow. This SHOULD be contained in the consumer’s CDR Receipt. This SHOULD also be accessible in the consumer dashboard as part of the data sharing arrangement details. Note 1: The information to be included is limited to the following standards: CDR Protections; Review; Data Handling; Complaints; and Insight Records. The scope of information to include will depend on the accredited person’s specific implementation. Note 2: This standard does not alter any existing rules obligations for CDR receipts or dashboards.

Consent Standards, Disclosure Consent: Non-Accredited Person Disclosure Notification, Disclosure consent: Notification record

1CO5.01.41

01. Business consumer disclosure consent - Bundled CDR consents

42

CX Guideline
MAY

Data recipients should only request a business consumer statement if they have verified the consumer is a business consumer — per CDR Rule 1.10(9) — and reasonably expect them to be intending to use the service for business purposes. Appropriate pre-consent and onboarding experiences can assist with funnelling consumers towards the most appropriate consent flow for their needs. This can reduce cognitive load for non-business consumers, and prevent consumers from inadvertently providing a business consumer statement.

CDR Rule 1.10(9)

1CO5.01.42

01. Business consumer disclosure consent - Bundled CDR consents

43

CX Guideline
MAY

The rules do not allow an individual without an active ABN to be treated as a CDR business consumer.

ACCC CDR business consumers - Fact sheet

1CO5.01.43

01. Business consumer disclosure consent - Bundled CDR consents

44

CX Guideline
MAY

Inline with CDR Rule 1.10A(9), when verifying the consumer is not an individual or has an active ABN, data recipients should be satisfied that the evidence given — such as the ABN — is current and relates to the consumer.

CDR rule 1.10A(9)

1CO5.01.44

01. Business consumer disclosure consent - Bundled CDR consents

45

CX Guideline
MAY

In accordance with CDR Rule 4.11(1)(bb), data recipients must invite a business consumer to give a business consumer statement in the consent flow. This invitation should be presented upfront. Doing so can help data recipients determine the appropriate consent duration and customer data language standards to surface, and whether a business consumer disclosure consent can be requested.

CDR Rule 4.11(1)(bb)

1CO5.01.45

01. Business consumer disclosure consent - Bundled CDR consents

46

CX Guideline
MAY

Data recipients may choose to present data holder selection screens before or after the data request occurs.

1CO5.01.46

01. Business consumer disclosure consent - Bundled CDR consents

47

CX Guideline
MAY

While data recipients may choose to present the data holder selection screens before or after the data request occurs, for disclosure consents recipients must ensure they meet the CX Standard Disclosure consent: Collection source as part of the data request. In some instances, this may require the data holder selection to be presented upfront.

Consent Standards, Disclosure consent: Collection source

1CO5.01.47

01. Business consumer disclosure consent - Bundled CDR consents

48

CX Guideline
MAY

Data recipients should present data holder brands in a way that is intuitive and allows consumers to search, sort and filter.

CX Research: Other 2025 (unpublished) | 10 Usability Heuristics for User Interface Design (Nielsen): Match Between the System and the Real World; Flexibility and efficiency of use

1CO5.01.48

01. Business consumer disclosure consent - Bundled CDR consents

49

CX Guideline
MAY

Data recipients should list data holder brands in an easily scannable way. This can be done alphabetically or contextually (for example, starting with popular data holders).

10 Usability Heuristics for User Interface Design: Flexibility and efficiency of use (Nielsen)

1CO5.01.49

01. Business consumer disclosure consent - Bundled CDR consents

51

CX Guideline
MAY

This flow demonstrates bundled collection, use, and business consumer disclosure consents. Data recipients may propose a consent duration of up to 7 years to business consumers for permitted consents under 1.10A(10). Other consents, such as collection consents (and the corresponding data holder authorisations), are limited to a maximum of 12 months. Data recipients may choose to propose durations that differ based on the consent type. If this approach were taken, collection consent renewals would still need to be requested at least every 12 months, inline with the collection duration originally consented to. Data recipients may alternatively choose to propose a single duration of up to 12 months for all the requested consents, despite being able to request up to 7 years for the use and disclosure consent. This would allow the data recipient to invite the consumer to renew all the consent types in a single action.

CDR Rules 1.10A(10), 4.11(1)(b), 4.12(1)–(1A)

1CO5.01.51

01. Business consumer disclosure consent - Bundled CDR consents

52

CX Guideline
MAY

In accordance with CDR Rule 1.10A(10), a business consumer statement cannot be made in relation to a collection consent. As such, CDR Rule 4.12(1) stipulates that the maximum duration for collection consent is 12 months.

CDR Rule 1.10A(10), 4.12(1)

1CO5.01.52

01. Business consumer disclosure consent - Bundled CDR consents

53

CX Guideline
MAY

Data recipients should use their discretion to determine whether a step to select a non-Accredited Person is required for their service. For example, the selection step may be necessary where the data recipient offers a range persons to whom the consumer can disclose. By contrast, the selection step may not be necessary where the consumer has a pre-existing relationship with a non-Accredited Person and the data recipient can reasonably assume that the consumer is engaging their service to disclose their data to this non-AP.

CDR Rule 4.11(1)(ba)

1CO5.01.53

01. Business consumer disclosure consent - Bundled CDR consents

54

CX Guideline
MAY

Data recipients should only present business consumers with a pre-selected duration of more than 12 months where the service reasonably requires this and in compliance with the data minimisation principle, CDR Rule 1.8.

CDR Rule 1.8

1CO5.01.54

01. Business consumer disclosure consent - Bundled CDR consents

55

CX Guideline
MAY

Data recipients will need to explain how the time period complies with the data minimisation principle (DMP). This is required for data that is yet to be generated (e.g. for an ongoing consent) as well as historical data (e.g. for collection on a 'single occasion'). Example DMP statement for data that is yet to be generated: We need to collect and use your data for 12 months so [we can update your financial position in real-time] to [deliver accurate and tailored personal financial management]. Example DMP statement for historical data: We need to collect the last 12 months of your data so [we can assess seasonal changes] to [provide an accurate energy comparison].

CDR Rule 4.11(3)(c), 1.8 | OAIC Chapter C: Consent (Data minimisation principle) | CX Research 1, 3

1CO5.01.55

01. Business consumer disclosure consent - Bundled CDR consents

56

CX Guideline
MAY

When data is requested and accessed, language used to describe the data must be described in accordance with the relevant CX standards; • ‘Data Language Standards: Language to be used’ and ‘Data Language Standards: Detailed scope requests’ applies when describing unmodified data from data holder(s). • ‘Consent Standards, Disclosure consent: Collection source’ applies to any data collected, but can be stated once where the collection source is the same for all data. • ‘Consent Standards, Disclosure Consent: Descriptions of Data to be Collected and Disclosed’ applies when describing any dataset. 

Data Language Standards: Common | Consent Standards

1CO5.01.56

01. Business consumer disclosure consent - Bundled CDR consents

57

CX Guideline
MAY

Data recipients should identify whether the user is sharing individual or non-individual accounts in order to surface the correct data language.

CX Workshop: Error handling

1CO5.01.57

01. Business consumer disclosure consent - Bundled CDR consents

58

CX Guideline
MAY

Data recipients should make the consent process as easy to understand as possible. Data recipients should nudge consumers to be more privacy conscious and should use appropriate interventions to mitigate cognitive overload, facilitate comprehension, and provide transparency and consumer control. This can be done in a variety of ways, including through the use of design patterns like progressive disclosure, micro and/or descriptive copy, and with the use of microinteractions.

CX Research 8, 19

1CO5.01.58

01. Business consumer disclosure consent - Bundled CDR consents

59

CX Guideline
MAY

Data recipients should present the purpose of the consent request in relation to each data cluster unless this statement applies equally to all datasets. If the statement applies equally to all datasets, data recipients should present this to the consumer clearly in relation to all of the datasets.

CDR Rule 4.11(3)(c), 1.8

1CO5.01.59

01. Business consumer disclosure consent - Bundled CDR consents

60

CX Guideline
MAY

Data recipients should also include a link to their specific page on www.cdr.gov.au/find-a-provider for accreditation verification purposes.

1CO5.01.60

01. Business consumer disclosure consent - Bundled CDR consents

61

CX Guideline
MAY

Where a data recipient presents a duration over 12 months for a consent that includes a business consumer statement, they must give the consumer at least one option of 12 months or less, to meet CDR Rule 4.12(1A)(b). For example, if a data recipient presents a 3 year duration, they might offer a 12 month option, a 6 month option, or both, but at least one must be offered. Data recipients are not required to allow the consumer to choose an alternative duration where durations of 12 months or less are proposed. However, data recipients may voluntarily provide this choice. When presenting duration options, data recipients should present consumers with a limited selection of duration options to reduce cognitive load. The options presented should represent the most common and/or most appropriate durations for the service being offered and be in compliance with the data minimisation principle.

CDR Rule 4.12(1A)(b) | 10 Usability Heuristics for User Interface Design: Visibility of system status (Nielsen)

1CO5.01.61

01. Business consumer disclosure consent - Bundled CDR consents

62

CX Guideline
MAY

To build consumer trust and confidence, data recipients should surface information about data deletion. This may include details from their CDR policy, as stated in CDR Rule 7.2(4)(k), and a link to read the policy.

CDR Rule 7.2(4)(k) | CX Research: 2019 Phase 1 report; 2019 Phase 2, Stream 3 report; 2020 Phase 3, Round 3 report; 2021 Disclosure Consent report

1CO5.01.62

01. Business consumer disclosure consent - Bundled CDR consents

63

CX Guideline
MAY

Data recipients should educate consumers about data sharing with the CDR, which may include references to the CDR protections. CX research has found that including this information increases familiarity, trustworthiness, propensity to consent, and increase the chances of adoption and successful completion.

1CO5.01.63

01. Business consumer disclosure consent - Bundled CDR consents

64

CX Guideline
MAY

CX research suggested that further information on data handling, including from government sources, can aid comprehension and confidence for Sceptic, Assurance Seeker and Sensemaker behavioural archetypes. Based on these insights, data recipients are encouraged to provide a link to OAIC’s guidance on Privacy Safeguard 12, which outlines information on data security and redundant data handling.

CDR Privacy Safeguard Guidelines: Privacy Safeguard 12 | CX Research: 2021 Disclosure Consent report

1CO5.01.64

01. Business consumer disclosure consent - Bundled CDR consents

65

CX Guideline
MAY

Data recipients are encouraged to provide links to the non-accredited person’s data handling information for the consumer to review. CX research and consultation suggested that accurate information on data handling provided by the non-accredited person would increase trustworthiness and consumer comfort.

CX Research: 2021 Disclosure Consent report

1CO5.01.65

01. Business consumer disclosure consent - Bundled CDR consents

66

CX Guideline
MAY

If the non-accredited person does not have a Privacy Policy, data recipients are encouraged to provide the consumer with other details; • to contact the non-accredited person; or • to review up-to-date information on the non-accredited person's data handling policies.

CX Research: 2021 Disclosure Consent report

1CO5.01.66

01. Business consumer disclosure consent - Bundled CDR consents

67

CX Guideline
MAY

Data recipients should send CDR receipts via the consumer's preferred delivery channels, other than through the consumer dashboard.

1CO5.01.67

01. Business consumer disclosure consent - Bundled CDR consents

68

CX Guideline
MAY

As per CDR Rule 4.18, data recipients are required to provide CDR receipts. Where separate consents are granted in a single flow, data recipients may provide a single CDR receipt that contains the details of each consent, or separate CDR receipts per consent. The CX Guidelines demonstrate two examples of intuitive groupings for CDR receipts: 1. collection and use consent details in one CDR receipt, and disclosure consent details in a separate CDR receipt; 2. consolidated receipt for collection, use and disclosure. Data recipients should use their discretion when grouping CDR receipts. Data recipients may consider aligning to how the consents were granted to match the consumers' mental model.

CDR Rule 4.18

1CO5.01.68

01. Business consumer disclosure consent - Bundled CDR consents

69

CX Guideline
MAY

The CX Standards for CDR Receipts take effect on 14 July 2025. The existing requirements regarding CDR receipts will continue to apply until the relevant data standards are made and in effect, as per the transitional provision outlined in CDR Rule 503 (and 506 for CDR representatives). Data recipients should refer to the CDR Rules as they were in effect from 22 July 2023 to 11 November 2024 for details of their obligations with regards to CDR receipts until this date.

CDR Rules 4.18 and 503; 4.20O and 506 | Notification Standards, CDR Receipts

1CO5.01.69

01. Business consumer disclosure consent - Bundled CDR consents

70

CX Standard
MUST

Data holders and data recipients MUST state in consumer-facing interactions and communications that third parties do not need consumer passwords to access CDR data. The exact phrasing of this is at the discretion of the data holder and data recipient. Note: In this context, 'third parties' refers to entities on the ADR-side and does not include any third parties that the data holder may engage.

Authentication Standards, Common Authentication Standards, Authentication: Passwords

1CO5.01.70

01. Business consumer disclosure consent - Bundled CDR consents

71

Common Standard

Data recipients MUST implement Redirect to App in accordance with the relevant consumer experience authentication and security profile standards. Data recipients MAY implement Redirect to App ahead of the date specified in the Future Dated Obligations schedule. Note: As per the future dated obligation schedule, data recipients subject to this standard are required to implement Redirect to App on and from 10 May 2027.

Authentication Schedule, Redirect to App, Data Recipients

1CO5.01.71

01. Business consumer disclosure consent - Bundled CDR consents

72

Common Standard
MUST

Where Redirect to App is unable to be used for the purposes of CDR authentication: • Data recipients MAY provide decoupled consent experiences that facilitate separation of the Consumption Device from the authorisation flow. • Data holders MAY provide decoupled authorisation experiences that facilitate separation of the Consumption Device from the Authentication Device. If implemented, data holders and data recipients MUST support decoupled authentication in accordance with any relevant consumer experience authentication and security profile standards.

Authentication Schedule, Decoupled Authentication

1CO5.01.72

01. Business consumer disclosure consent - Bundled CDR consents

73

CX Guideline
MAY

Data recipients should populate the data holder/provider selection list using the data holder brandName field provided in the CDR Register APIs. For additional guidance on surfacing brand names and brand groups, see the CX Guidelines on Consent: Collection and use consents - Provider selection for white labeled brands.

CDR Support Portal: Brands in the CDR ecosystem

1CO5.01.73

01. Business consumer disclosure consent - Bundled CDR consents
‣
See prototype

Note: Some interactions and screens have been omitted for simplicity.

Download open source asset

Open source design assets are created in Figma for the purposes of assisting implementation. This Figma file contains annotated wireframes and working prototypes for Business consumer disclosure consents, including:

  • Detached flow
  • Bundled CDR Consents
icon
Download design asset
Item
File
Date released
Version introduced
1CO5. Business consumer disclosure consent v1.36.0.2026.03.18
1CO5. Business consumer disclosure consent v1.36.0.2026.03.18.fig
Mar 18, 2026
1.36.0

For past versions, refer to Change log.

‣
About open source assets

Open sources design assets are provided in the form of version-controlled Figma files. These assets contain the annotated wireframe and working prototype published on this page, and have been reviewed for accessibility compliance. Assets are partially conformant to Web Content Accessibility Guidelines (WCAG) 2.1 level AA. These assets do not tend to accessible code and instead focus on visual presentation and readability.

The assets use the GOLD Design System; component rationale, accessibility support, and code documentation is available in the GOLD Design System website.

For more details, see Open Source Assets.

About this page

References

The artefacts on this page were informed by the following sources.

Title
Author
Date published
URL
Type
CDR Support Portal: Brands in the CDR ecosystem
Australian Competition and Consumer Commission (ACCC)
Mar 10, 2026
cdr-support.zendesk.com
Guidance
Change Request 715: CX Guidelines | Changes stemming from CD376 (White label brand arrangements)
Data Standards Body (DSB)
Dec 11, 2025
github.com
Consultations
Consultation Draft 376 - White label brand arrangements - Draft Standards
Data Standards Body (DSB)
Nov 28, 2025
github.com
Consultations
Change Request 701: CX Guidelines | Data Language Standards changes stemming from CD367
Data Standards Body (DSB)
Jun 6, 2025
github.com
Consultations
Change Request 700: CX Guidelines | Redirect to App (R2A) CX Guidelines Changes
Data Standards Body (DSB)
Jun 5, 2025
github.com
Consultations
Change Request 691: CX Guidelines | Expanding Amending BCDC CX Guidelines
Data Standards Body (DSB)
Apr 15, 2025
github.com
Consultations
Consultation Draft 367: March 2025 Rules - Draft Standards
Data Standards Body (DSB)
Mar 14, 2025
github.com
Consultations
Change Request 674: CX Guidelines | Updates stemming from 2024 Consent Review changes
Data Standards Body (DSB)
Oct 2, 2024
github.com
Consultations
Consumer Data Right Rules: consent and operational enhancement amendments consultation
The Treasury
Aug 9, 2024
treasury.gov.au
Consultations
CDR business consumers - Fact sheet
Australian Competition and Consumer Commission (ACCC)
Jul 9, 2024
www.cdr.gov.au
Guidance
Decision Proposal 333: Business Consumer Provisions
Data Standards Body (DSB)
Oct 21, 2023
github.com
Consultations
Consumer Data Right rules – Consent Review and operational enhancements design papers
The Treasury
Aug 25, 2023
treasury.gov.au
Consultations
Decision Proposal 276: July 2023 Rules | Standards Impacts
Data Standards Body (DSB)
Nov 3, 2022
github.com
Consultations
Disclosure Consent Research Report
Data Standards Body (DSB)
Apr 4, 2022
cx.dsb.gov.au
Research
10 Usability Heuristics for User Interface Design (Error prevention)
Nielsen Norman Group (NNG)
Apr 24, 1994
nngroup.com
Other

Last updated

This page was updated @Sep 12, 2025

Have your say

Community consultations and maintenance are part of our ongoing process. Here’s how you can get involved:

  • Request new Guidelines or changes to existing Guidelines through the CX Guidelines Consultation process
  • Request new Standards or changes to existing Standards through the Standards Maintenance process
  • Log a ticket for any questions about the rules, standards, or guidelines through the CDR Support Portal
  • Email your feedback to cx@dsb.gov.au
image

Quick links to CX Guidelines:

Overview

Consent

Authenticate

Authorise

Consent Management

Notifications

Accessibility statement

→ cx@dsb.gov.au → cx.dsb.gov.au | cds.gov.au

The Consumer Data Standards Program is part of Treasury. Copyright © Commonwealth of Australia 2023. The information provided on this website is licensed for re-distribution and re-use in accordance with Creative Commons Attribution 4.0 International (CC-BY 4.0) Licence.