Resources · CDR for business, explained

Do you need CDR accreditation to receive your business customers’ bank data? No.

Since 28 November 2023, Australia’s Consumer Data Right (CDR) has let a business consent to its bank data being shared with the software it uses. The software provider needs no accreditation of its own. Here is the rule, what it asks of your customer, and what accreditation would have involved instead.

The rule

Business consumer disclosure consent

The CDR is the legislation behind open banking in Australia. It gives the owner of data, including a business, the right to have that data shared with a third party it chooses. Normally the third party has to be an Accredited Data Recipient (ADR): an organisation the regulator has checked and approved to hold CDR data.

In November 2023 the rules gained a specific path for businesses. A business consumer disclosure consent (BCDC) is a consent given by a business that authorises an accredited data recipient to disclose its CDR data to a person it names. The ACCC’s own fact sheet lists who that person can be: bookkeepers, software providers, consultants and other advisers who are not accredited.

In plain terms: the business says “share my bank data with the software I use”, an accredited provider collects it from the bank, and the software provider receives it. No accreditation on the software provider’s side.

From the CDR Rules

Who counts as a business

A “CDR business consumer” is a consumer that the accredited provider has taken reasonable steps to confirm either is not an individual (a company, a trust, a partnership, an incorporated association) or has an active ABN. A sole trader with an ABN qualifies. An individual without one does not.

ACCC, CDR business consumers fact sheet, July 2024 · CDR Rules 1.10A(9) and 1.10A(11)

How business consent works

What your customer sees, step by step

Five steps. Your customer does the first three once; after that the data keeps flowing for as long as the consent and the bank authorisation run.

1. It starts in your product

Your customer clicks “connect bank accounts” in your app, or on a page Skript hosts for you. The rules only allow business consent for a customer that is not an individual, or that holds an active ABN, and the accredited provider has to confirm that before it asks the bank for anything. Skript does that check, so this path is for the businesses on your platform, not their owners as individuals.

2. The consent screen

On Skript’s consent screen the business chooses what to share, names your product as the recipient, and confirms that the data is for a business purpose. That confirmation is called a business consumer statement. The screen also tells them, in the words the standards require, that once the data reaches you it is no longer regulated under the CDR, and how to complain if something goes wrong.

3. The bank

The business is sent to its own bank to log in and authorise the sharing. For a company or partnership, the person doing this is a nominated representative: someone the business has told the bank may share its data. They pick the accounts, and the bank confirms the authorisation. Bank authorisations run for up to 12 months and are renewed the same way.

4. Data flows through Skript’s API

Skript collects the data from the bank under its own accreditation and delivers it to you: transactions, balances, account details including BSB and account number, refreshed daily, intra-day or hourly, with at least two years of history to start from where the bank provides it.

5. Renewal and control

The business consent to share with you can run for up to seven years, and the rules require that a business is always offered a 12-month-or-shorter option too. The bank authorisation is renewed at the bank before its 12 months are up. The business can withdraw an authorisation from its bank’s consumer dashboard at any time, and the data stops.

What you do with it

Once disclosed to you, the data sits under your own privacy obligations rather than the CDR’s. Skript only collects and passes on what your product reasonably needs, because the CDR’s data-minimisation principle applies to us. Your part is the same as for any other customer data you hold: a privacy policy that covers it, and sensible handling.

Skript’s accreditation

What our accreditation covers, and what it doesn’t

Skript is an unrestricted Accredited Data Recipient: the highest level of CDR accreditation, which lets us collect data straight from the banks under our own accreditation, so you need none of your own.

Covered by Skript

Collecting the data from over 110 Australian banks. Confirming the account holder is a business, as the rules require. Running the consent flow to the standards, including the business consumer statement and the required notices. Holding the data under the CDR privacy safeguards while it is with us. Accredited since 2022, ID ADRBNK2010.

Yours to handle

What you build with the data. Your own privacy policy and handling once the data is with you. Telling your customers, in your own terms, what you use their bank data for. The rules also say we cannot make naming a recipient a condition of our service, so the choice to share with you is always the business’s.

Not what we do

We do not lend our accreditation to other companies, and we do not serve individuals’ data. Skript works with two kinds of access only: a business’s own data (Subskript), and business consent for the platforms businesses run on (Superskript and Superskript Aggregator). If you need individuals’ data, we are not your provider, and we will say so on the first call.

Common questions

Questions product teams ask

Is business consent a loophole?

No. It is a rule the government added deliberately, in the Competition and Consumer (Consumer Data Right) Amendment Rules (No. 1) 2023, after consultation, because businesses share their financial data with software and advisers as a matter of course. The ACCC’s fact sheet says the change is intended to support participation by a broader range of businesses. It sits alongside the accreditation regime rather than around it: an accredited provider still collects the data and still carries the CDR obligations.

Does it cover sole traders?

Yes, if they have an active ABN. The rules treat any consumer with an active ABN as a business consumer, and Skript checks the ABN before making the request. A person without an ABN is an individual under the CDR, and Skript does not serve individuals’ data.

How long does a consent last?

Two clocks run. The business’s consent to share with your product can run for up to seven years, and a business must always be offered a 12-month-or-shorter option as well. The authorisation the business gives its bank lasts up to 12 months and is renewed at the bank, the same way it was given.

What happens to the data once it reaches us?

Once an accredited provider discloses CDR data to a non-accredited recipient under a business consent, that copy is no longer regulated as part of the CDR. Your customer is told this at the consent screen, in the words the standards require. From that point you handle it under your own privacy obligations, the same as any other customer data you hold. Skript’s copy stays under the CDR privacy safeguards.

Our customers have accounts that need two people to sign. Will consent work?

Usually, yes. Signing rules on payments and the right to share data are set up separately at the bank. A business nominates one or more representatives for data sharing, and once nominated, a representative can authorise sharing on their own. Where a business has not nominated anyone, the bank cannot let it share, and the bank’s own screens point the business to its nomination process. The practical fix is to tell customers before they start: the person connecting the accounts needs to be a nominated representative. If you have a particular bank or account structure in mind, ask us; we have seen most of them.

Where is the rule written down?

The Competition and Consumer (Consumer Data Right) Rules 2020, rule 1.10A, define a CDR business consumer, a business consumer statement and a business consumer disclosure consent. The ACCC’s CDR business consumers fact sheet explains them in plain terms, and the Data Standards Body’s consumer experience guideline sets out what the consent screen must say. Our Open Banking page covers the wider picture, and the FAQs answer the shorter questions.

Business bank data,
no accreditation needed.

Sandbox keys in minutes. No sales call, no waitlist.