The Consumer Data Right (CDR) is Australian legislation that gives the owner of data — including businesses — control over it, and a safe, regulated way to share it, via an accredited data recipient like Skript, with the services they choose. In banking, it's what makes Open Banking work.
Our Open Banking page goes into more detail, including how the CDR compares with direct bank APIs and screen scraping.
Yes. Skript has been an Unrestricted Accredited Data Recipient (ADR) under the CDR since 2022 (accreditation ID ADRBNK2010).
“Unrestricted” is the highest level of CDR accreditation. It means Skript collects and holds bank data directly from the banks under its own accreditation, rather than sitting behind another provider’s — and it is why you don’t need any accreditation of your own.
Our accreditation is active, meaning we have live connections to the banks (“data holders”) in the CDR ecosystem.
For business data, no. There are two ways in, and neither needs CDR accreditation on your side:
Skript holds the accreditation as an unrestricted Accredited Data Recipient (ADR) and collects the data with the account holder's consent. You build the product. The rule, what it asks of your customer and what accreditation would have involved are all on our accreditation explainer.
No. It is a rule the government added deliberately in the Competition and Consumer (Consumer Data Right) Amendment Rules (No. 1) 2023, in force since 28 November 2023, because businesses share financial data with software and advisers as a matter of course. The ACCC’s fact sheet says the change is intended to support participation by a broader range of businesses. An accredited provider still collects the data and still carries the CDR obligations; the business simply chooses who receives it. Read the rule in full.
Yes, if they have an active ABN. The CDR Rules treat any consumer that is not an individual, or that holds an active ABN, as a business consumer, and Skript confirms that before requesting data. A person without an ABN is an individual under the CDR, and Skript does not serve individuals’ data.
Two clocks run. The business’s consent to share with your product can run for up to seven years, and the rules require that a business is always offered a 12-month-or-shorter option as well. The authorisation the business gives its bank lasts up to 12 months and is renewed at the bank, the same way it was given. The business can withdraw a bank authorisation from its bank’s consumer dashboard at any time, and the data stops.
Once an accredited provider discloses CDR data to a non-accredited recipient under a business consent, that copy is no longer regulated as part of the CDR. Your customer is told this at the consent screen, in the words the standards require. From that point you handle it under your own privacy obligations, the same as any other customer data you hold. Skript’s copy stays under the CDR privacy safeguards.
Usually, yes. Signing rules on payments and the right to share data are set up separately at the bank. Under the CDR Rules a company or partnership nominates one or more people, aged 18 or over, as nominated representatives for data sharing, and once nominated a representative can authorise sharing on their own. Where nobody has been nominated, the bank cannot let the business share, and the bank’s own screens point it to the nomination process. The practical fix is to tell customers in advance: the person connecting the accounts needs to be a nominated representative. More on business accounts and nominated representatives.
The Competition and Consumer (Consumer Data Right) Rules 2020, rule 1.10A, define a CDR business consumer, a business consumer statement and a business consumer disclosure consent. The ACCC’s CDR business consumers fact sheet explains them in plain terms, and the Data Standards Body’s consumer experience guideline sets out what the consent screen must say. Our accreditation explainer pulls it together with sources.
Two. A business accessing its own bank data (Subskript), and a business consenting to share its bank data with a platform it uses — business consumer disclosure consent, or BCDC (Superskript and Superskript Aggregator).
That's deliberate. We're business data specialists, and these are the two routes that fit business data. They also keep the compliance burden off you: Skript holds the accreditation as an unrestricted Accredited Data Recipient (ADR), so you don't need any accreditation of your own — you build the product.
We don't offer any other CDR access arrangements, and we work with business account data only.
Skript is connected to over 110 banks in Australia, including:
Our pricing is public. Subskript starts from $99/month ex-GST, depending on how often you need data refreshed — 5 accounts included, priced per account with no transaction caps, month-to-month, no setup fee, no lock-in. See the pricing page for the full breakdown.
For platforms serving business customers, Superskript starts from $1,250/month and Superskript Aggregator from $2,500/month; both are scoped with our team. Get in touch and we'll put a number on it.
No. Every plan is priced per connected bank account, and transactions are not counted or capped. A busy trading account and a quiet one cost the same, and there is no overage charge on any plan.
We’ll only speak for ourselves, so here is what you can check on our pricing page. The price is published, including the starting price for the enterprise plans. There is no setup fee. Nothing is metered by transaction, so there are no caps and no overage. Billing is month to month with no lock-in. You can sign up and connect your accounts today, without a sales call. You choose the refresh — daily, five times a day or hourly. And we only do business bank data, so the consent flow, the data fields and the support are built for business accounts rather than adapted from a consumer product.
If the provider you’re comparing us with does all of that too, compare us on the data and the service. If not, that’s the difference.
As an unrestricted Accredited Data Recipient (ADR) we’re held to the CDR’s information-security rules, not just our own good intentions.
In practice: we only ever collect data with the account holder’s consent; we never see or store your bank login; we don’t sell your data; and we delete or de-identify it once it’s no longer needed or consent is withdrawn.
Sign-up is instant. Sign up to the portal to get sandbox keys in minutes, read the API documentation and test against sandbox data — no sales call, no waitlist.
For Superskript or Superskript Aggregator, or anything else, get in touch and we'll scope it with you.
Sandbox keys in minutes. No sales call, no waitlist.