Since 28 November 2023, Australia’s Consumer Data Right (CDR) has let a business consent to its bank data being shared with the software it uses. The software provider needs no accreditation of its own. Here is the rule, what it asks of your customer, and what accreditation would have involved instead.
The CDR is the legislation behind open banking in Australia. It gives the owner of data, including a business, the right to have that data shared with a third party it chooses. Normally the third party has to be an Accredited Data Recipient (ADR): an organisation the regulator has checked and approved to hold CDR data.
In November 2023 the rules gained a specific path for businesses. A business consumer disclosure consent (BCDC) is a consent given by a business that authorises an accredited data recipient to disclose its CDR data to a person it names. The ACCC’s own fact sheet lists who that person can be: bookkeepers, software providers, consultants and other advisers who are not accredited.
In plain terms: the business says “share my bank data with the software I use”, an accredited provider collects it from the bank, and the software provider receives it. No accreditation on the software provider’s side.
A “CDR business consumer” is a consumer that the accredited provider has taken reasonable steps to confirm either is not an individual (a company, a trust, a partnership, an incorporated association) or has an active ABN. A sole trader with an ABN qualifies. An individual without one does not.
ACCC, CDR business consumers fact sheet, July 2024 · CDR Rules 1.10A(9) and 1.10A(11)
Accreditation exists for organisations that collect CDR data from banks themselves. It is a serious undertaking, and for a software provider serving businesses it is one you can skip. The ACCC, as the accreditor, publishes what it takes.
| Requirement | What the ACCC asks for | Accredited provider (Skript) | Software provider under business consent |
|---|---|---|---|
| Fit and proper person | Signed declarations about the organisation and the people who run it; the ACCC may run background checks. | ||
| Information security | The controls in Schedule 2 of the CDR Rules, with evidence in the form the ACCC’s supplementary information-security guidelines set out, such as an independent assurance report over those controls. | ||
| Dispute resolution | Internal complaints handling to ASIC Regulatory Guide 271, and membership of the Australian Financial Complaints Authority (AFCA). | ||
| Insurance | Cover that meets the ACCC’s supplementary insurance guidelines. | ||
| Time and cost to apply | No application fee. The ACCC aims to check an application for completeness within one to two weeks, and says assessment and decision may take approximately four months. | Done, 2022 | Not needed |
| Ongoing obligations | The CDR privacy safeguards, the data standards, record-keeping and reporting to the regulators, for as long as you hold CDR data. |
Source: ACCC, CDR accreditation guidelines, version 6, 26 August 2025, sections 2.4.3, 3.1 and 4. The guidelines describe two levels of accreditation; Skript holds the unrestricted level, which is the one that allows a provider to collect data straight from the banks.
Five steps. Your customer does the first three once; after that the data keeps flowing for as long as the consent and the bank authorisation run.
Your customer clicks “connect bank accounts” in your app, or on a page Skript hosts for you. The rules only allow business consent for a customer that is not an individual, or that holds an active ABN, and the accredited provider has to confirm that before it asks the bank for anything. Skript does that check, so this path is for the businesses on your platform, not their owners as individuals.
On Skript’s consent screen the business chooses what to share, names your product as the recipient, and confirms that the data is for a business purpose. That confirmation is called a business consumer statement. The screen also tells them, in the words the standards require, that once the data reaches you it is no longer regulated under the CDR, and how to complain if something goes wrong.
The business is sent to its own bank to log in and authorise the sharing. For a company or partnership, the person doing this is a nominated representative: someone the business has told the bank may share its data. They pick the accounts, and the bank confirms the authorisation. Bank authorisations run for up to 12 months and are renewed the same way.
Skript collects the data from the bank under its own accreditation and delivers it to you: transactions, balances, account details including BSB and account number, refreshed daily, intra-day or hourly, with at least two years of history to start from where the bank provides it.
The business consent to share with you can run for up to seven years, and the rules require that a business is always offered a 12-month-or-shorter option too. The bank authorisation is renewed at the bank before its 12 months are up. The business can withdraw an authorisation from its bank’s consumer dashboard at any time, and the data stops.
Once disclosed to you, the data sits under your own privacy obligations rather than the CDR’s. Skript only collects and passes on what your product reasonably needs, because the CDR’s data-minimisation principle applies to us. Your part is the same as for any other customer data you hold: a privacy policy that covers it, and sensible handling.
A company is not a person, so someone has to act for it. Under the CDR Rules a business or partnership must nominate at least one individual, aged 18 or over, as a nominated representative before it can share any data. That person can give, change and withdraw authorisations on the business’s behalf. They are not the consumer; the business is.
Banks are required to give business customers a way to nominate representatives and revoke them, online or on paper, and most fold it into the account permissions they already manage. No particular role is automatically a nominated representative: a director, a finance manager or a bookkeeper can all be one, if the business says so. A business can also limit which accounts each representative may share.
If nobody has been nominated, the bank cannot let the business authorise sharing. In practice this is the step that trips up business onboarding. The consumer experience standards give banks a “request sharing rights” path to show when an account is unavailable for this reason, so the person at the bank’s screen is told what to do rather than left with a blank list. It still pays to warn your customers in advance: whoever will connect the accounts should be set up as a nominated representative at the bank first.
Source: ACCC, Nominated representatives of non-individuals and partnerships in CDR, fact sheet version 4, October 2025, sections 2.1 to 2.8.
Nominating a representative and authorising data sharing are separate things. For a partnership, the ACCC says the bank and the customer can agree that all partners, some partners or one partner must approve a nomination. Once nominated, a representative authorises sharing on their own. A two-to-sign payment rule on the account does not, by itself, mean two people must approve data sharing; it depends on what the business set up with its bank.
Skript’s consent flow is built for business account holders, including multi-signatory accounts, and can be hosted by Skript or embedded in your app. See Superskript.
Skript is an unrestricted Accredited Data Recipient: the highest level of CDR accreditation, which lets us collect data straight from the banks under our own accreditation, so you need none of your own.
Collecting the data from over 110 Australian banks. Confirming the account holder is a business, as the rules require. Running the consent flow to the standards, including the business consumer statement and the required notices. Holding the data under the CDR privacy safeguards while it is with us. Accredited since 2022, ID ADRBNK2010.
What you build with the data. Your own privacy policy and handling once the data is with you. Telling your customers, in your own terms, what you use their bank data for. The rules also say we cannot make naming a recipient a condition of our service, so the choice to share with you is always the business’s.
We do not lend our accreditation to other companies, and we do not serve individuals’ data. Skript works with two kinds of access only: a business’s own data (Subskript), and business consent for the platforms businesses run on (Superskript and Superskript Aggregator). If you need individuals’ data, we are not your provider, and we will say so on the first call.
No. It is a rule the government added deliberately, in the Competition and Consumer (Consumer Data Right) Amendment Rules (No. 1) 2023, after consultation, because businesses share their financial data with software and advisers as a matter of course. The ACCC’s fact sheet says the change is intended to support participation by a broader range of businesses. It sits alongside the accreditation regime rather than around it: an accredited provider still collects the data and still carries the CDR obligations.
Yes, if they have an active ABN. The rules treat any consumer with an active ABN as a business consumer, and Skript checks the ABN before making the request. A person without an ABN is an individual under the CDR, and Skript does not serve individuals’ data.
Two clocks run. The business’s consent to share with your product can run for up to seven years, and a business must always be offered a 12-month-or-shorter option as well. The authorisation the business gives its bank lasts up to 12 months and is renewed at the bank, the same way it was given.
Once an accredited provider discloses CDR data to a non-accredited recipient under a business consent, that copy is no longer regulated as part of the CDR. Your customer is told this at the consent screen, in the words the standards require. From that point you handle it under your own privacy obligations, the same as any other customer data you hold. Skript’s copy stays under the CDR privacy safeguards.
Usually, yes. Signing rules on payments and the right to share data are set up separately at the bank. A business nominates one or more representatives for data sharing, and once nominated, a representative can authorise sharing on their own. Where a business has not nominated anyone, the bank cannot let it share, and the bank’s own screens point the business to its nomination process. The practical fix is to tell customers before they start: the person connecting the accounts needs to be a nominated representative. If you have a particular bank or account structure in mind, ask us; we have seen most of them.
The Competition and Consumer (Consumer Data Right) Rules 2020, rule 1.10A, define a CDR business consumer, a business consumer statement and a business consumer disclosure consent. The ACCC’s CDR business consumers fact sheet explains them in plain terms, and the Data Standards Body’s consumer experience guideline sets out what the consent screen must say. Our Open Banking page covers the wider picture, and the FAQs answer the shorter questions.
Sandbox keys in minutes. No sales call, no waitlist.