Open banking is the regulated framework under Australia's Consumer Data Right (CDR) that lets you authorise accredited third parties to access specific financial data held by your bank.
Also known as: bank data sharing, Consumer Data Right (CDR), CDR data sharing
Key points
- You never hand over your internet banking login: you consent on your bank's own screen and the accredited provider receives data through secure APIs.
- Consent is specific and revocable: it names the provider, data classes, purpose and duration, and you can withdraw it at any time.
- The ACCC accredits data recipients and enforces the CDR rules; the OAIC handles privacy under the Privacy Act.
- Lenders use it to verify income and expenses quickly for loan applications; businesses use it to link bank feeds to accounting software.
How open banking works
There are four participants. You, the consumer, own the data and give consent. The data holder (your bank or account provider) supplies data on request. An Accredited Data Recipient (ADR), which might be a fintech, a lender or an accounting platform, is accredited under the CDR rules to receive it. And the regulators set the rules, security standards and oversight.
The flow is the same every time. You choose a service and ask to connect. The service redirects you to your bank's consent page, where the screen lists who is asking, exactly which data classes, for what purpose and for how long. You log in with your bank, grant or refuse consent, and receive a receipt. The ADR then pulls only the authorised data through secure, encrypted APIs in a standard format, every access is logged, and you can view, manage or revoke the consent through the provider or your bank's data sharing dashboard.
What data can be shared
The common data classes are transaction history (debits, credits, payees and memos, subject to data minimisation), account balances and identifiers, product data such as interest rates, fees and features, and the identity and contact details needed to deliver the service. Future open finance phases may extend the CDR to superannuation, insurance and more detailed lending data.
The limits matter as much as the scope. ADRs never receive your passwords or PINs, because they operate through APIs rather than your login. Sensitive information outside the CDR scope is restricted. And the rules stop an ADR using your data for unsolicited marketing or reselling it without a separate, explicit consent.
Why it matters for lending
For consumers, the headline benefit is faster loan and mortgage pre-assessment, because the lender can verify income and expenses from the data rather than from statements you upload. It also powers budgeting apps that aggregate accounts and categorise spending, and makes switching products and comparing offers easier.
For small businesses the gains are practical: bank feeds flow straight into accounting software, and lenders offering working capital or invoice finance can assess cashflow in real time rather than from last year's financials. Before authorising any provider, confirm it is on the CDR participants register, limit the scope and duration to what the service actually needs, prefer read-only access, and check the access logs occasionally. If something goes wrong, the ADR's or bank's complaints process is the first step, then the OAIC for privacy issues or the ACCC for CDR breaches.
Example
A cafe owner applies for a working capital loan through an online lender. Instead of downloading and emailing months of bank statements, she chooses to share data through open banking. The lender's site redirects her to her bank's consent screen, which shows the lender's name, that it wants twelve months of transaction history and balances, why it wants them and for how long. She logs in with her bank and approves, and the lender receives the data through the CDR's secure APIs and can verify her income and expenses quickly. Once the loan is settled she revokes the consent from her bank's data sharing dashboard.
Not to be confused with
- Comprehensive credit reporting (CCR)
- comprehensive credit reporting is lenders sharing your repayment history with credit bureaus; open banking is you choosing to share your bank account data with an accredited provider
- Fintech
- fintech is the broad industry of technology-driven financial services; open banking is one regulated data-sharing framework those businesses can use
Frequently asked questions
Is open banking safe?
It is designed to be. Data recipients must be accredited and prove their security and governance, data moves through encrypted APIs limited to the consented scope, every consent and transfer is logged, and providers can only request the data they need. The OAIC and ACCC oversee it, and you never share your bank password. Residual risks are the same as any online service: use reputable, accredited providers.
Does open banking give apps access to my internet banking password?
No. You authenticate on your bank's own consent screen, and the accredited provider receives a scoped consent token and data through secure APIs. It never sees your login credentials or PIN, and its access is limited to the accounts, data types and duration you approved.
Can I revoke open banking consent?
Yes, at any time, either in the provider's settings or through your bank's data sharing dashboard. Revocation stops future access but does not undo lawful uses that already happened. Be aware that a lender may be unable to verify income or expenses without the data, which can affect how it assesses an application.
How do I check if a provider is accredited?
Look the provider up on the CDR participants register on the official Consumer Data Right website, which lists accredited data recipients and data holders. If a provider is not listed, it is not accredited to receive your data under the CDR, whatever its marketing says, and any request to share your bank data should be treated with suspicion.
Is open banking the same as open finance?
Not quite. Open banking is the banking sector of the Consumer Data Right, focused on bank account and product data. Open finance describes extending the CDR to other financial products and sectors, which may in future include superannuation, insurance and richer lending data, so that the same consent-based sharing applies across more of your financial life.
Related terms
ACCC
The ACCC is the Australian Competition and Consumer Commission, the national regulator that enforces competition and consumer law, covering misleading conduct, cartels, product safety and unfair contract terms.
Read definitionOAIC
The OAIC is the Office of the Australian Information Commissioner, Australia's independent privacy regulator, which enforces the Privacy Act, the Australian Privacy Principles and the Notifiable Data Breaches scheme.
Read definitionPrivacy Act
The Privacy Act 1988 is the Australian law that sets out how government agencies and many organisations must collect, use, disclose and correct personal information, including credit reporting data.
Read definitionFintech
Fintech (short for financial technology) is the use of software, data and modern infrastructure to deliver or improve financial services, from mobile payments and digital banking to online lending.
Read definitionComprehensive credit reporting (CCR)
Comprehensive credit reporting (CCR) is the system under which lenders share positive credit information, such as repayment history and credit limits, as well as defaults, on your credit file.
Read definitionData protection
Data protection is the legal duty of brokers and lenders to handle customers' personal information under the Privacy Act and the Australian Privacy Principles, from collection to secure destruction.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.