What Is the Difference Between Data Holder and Data Recipient?
Understand the roles of data holders and recipients in open banking, exploring their responsibilities, compliance, and impact on consumer data exchange.
In the digital age, particularly with the rise of open banking and the Consumer Data Right (CDR) framework, understanding the roles of data holders and data recipients is crucial. These two entities play pivotal roles in the secure and regulated exchange of consumer data. But what exactly differentiates them? This article will provide a clear explanation of these terms, explore their relevance in the financial sector, and offer practical insights into how businesses and consumers interact with them.
Understanding Data Holders and Data Recipients
What Is a Data Holder?
A data holder is an entity that holds consumer data and is obligated to share it with authorised third parties when the consumer gives their explicit consent. In Australia’s open banking system, for example, the four major banks—ANZ, Commonwealth Bank, NAB, and Westpac—are classified as data holders because they manage customer accounts and transactional data. They are required to provide this data to accredited parties when customers request it, as per the Consumer Data Right (CDR) legislation.
Key Responsibilities of a Data Holder:
- Store and Secure Data: Data holders manage consumer data and must protect it in accordance with privacy regulations such as the General Data Protection Regulation (GDPR) and Australia’s Privacy Act.
- Provide Data on Request: When a consumer requests that their data be shared with an accredited data recipient, data holders must securely and efficiently transfer the information.
- Compliance: Data holders must comply with the CDR framework, ensuring that data is shared safely, securely, and with full consent from the consumer.
Who Classifies as a Data Holder?
A data holder can include various types of entities that collect, store, and manage consumer data. Examples of data holders include:
Banks and Financial Institutions: Traditional banks that manage consumer accounts and transactional data.
Utility Companies: Providers of services such as electricity, gas, or water that hold data on consumer usage patterns.
Telecommunication Companies: Entities that manage customer data related to communication services.
Insurance Providers: Companies that maintain records of policyholders and claims, which constitute consumer data.
Public Sector Organisations: Government bodies that collect and manage data for public services and research.
These entities are required to adhere to data protection regulations and ensure that they share consumer data responsibly with accredited recipients.
What Is a Data Recipient?
A data recipient, also known as an accredited data recipient (ADR), is an entity authorised to access and use consumer data for specific purposes, as consented to by the consumer. Data recipients are often fintech companies or other businesses that use consumer data to offer personalised services such as financial planning, loan comparisons, or budgeting tools.
Accredited data recipients must meet stringent requirements and follow strict security protocols to be trusted with sensitive information. They must also ensure that the data is used only for the purpose agreed upon by the consumer and comply with regulations like the CDR and GDPR.
Key Differences Between Data Holder and Data Recipient

Role in Data Exchange:
- Data Holders manage and store the data. They control access to consumer data but are legally required to share it with authorised data recipients.
- Data Recipients access and use the data provided by holders, typically for offering personalised services to consumers.
Obligations:
- Data Holders must comply with consumer data requests and ensure the secure transmission of data to accredited recipients.
- Data Recipients must use the data responsibly, ensuring that it is applied only for the purposes the consumer consented to, while maintaining high levels of data security.
Accreditation:
- Data Holders are usually established institutions, like major banks, which are bound by regulatory frameworks.
- Data Recipients must become accredited under frameworks like the CDR before they can access consumer data, proving they meet all regulatory and security requirements.
How Do Data Holders and Data Recipients Interact?
The interaction between data holders and data recipients is governed by the CDR framework, which ensures that consumer data is shared safely and securely. When a consumer grants permission, the data holder provides access to the data recipient through secure APIs. This exchange allows recipients to use the data for a range of purposes, such as:
- Personalised Financial Services: Fintech companies may use consumer data to offer tailored budgeting tools or financial advice.
- Loan Comparisons: By accessing financial data, data recipients can help consumers find better loan or mortgage options.
- Energy Usage Insights: Energy providers may use consumer data to offer insights into energy usage patterns, helping consumers reduce their costs.
How Do Data Sharing Agreements Affect Data Holders and Data Recipients?
Data sharing agreements form the legal foundation for the interaction between data holders and data recipients. These agreements outline the terms and conditions for sharing consumer data and help ensure that both parties comply with the necessary regulatory frameworks.
Security and Compliance: These agreements establish the necessary protocols to ensure that data is exchanged securely. Data holders must ensure that data recipients meet stringent security standards, while recipients must agree to use the data strictly for the agreed purposes.
Liability: Data sharing agreements also define the responsibilities of each party in the event of a data breach. Both data holders and recipients may be held accountable if data is mishandled, but the agreement helps delineate liability based on where the breach occurs.
Consumer Consent: Agreements must clearly outline how consumer consent is obtained and managed. Data holders are responsible for ensuring that consent is valid and informed before sharing data with recipients. The recipient must also ensure that they do not misuse or exceed the consent given by the consumer.
By clearly defining these aspects, data sharing agreements play a vital role in protecting both consumers and businesses while fostering trust in the system.
What Legal and Compliance Differences Exist Between Data Holders and Data Recipients?
The regulatory landscape for data holders and data recipients differs in several key areas, primarily due to their distinct roles in the data-sharing ecosystem.
Data Holders:
- Compliance with Data Requests: Data holders must adhere to strict legal obligations to provide data to accredited recipients upon consumer consent. They must ensure the data is accurate and up-to-date and must comply with regulations like the CDR and GDPR.
- Security: Data holders are often required to invest heavily in cybersecurity to ensure that consumer data is stored safely, as any breach can result in significant penalties.
Data Recipients:
- Accreditation: Data recipients must become accredited by relevant regulatory bodies, such as the Australian Competition and Consumer Commission (ACCC), to be authorised to receive consumer data. This process involves proving that they can securely manage and process the data they receive.
- Purpose Limitation: Data recipients are legally bound to use the data only for the purpose specified in the consent agreement with the consumer. Any misuse or unauthorised processing of data can result in severe penalties.
While both data holders and data recipients have legal responsibilities under frameworks like the CDR and GDPR, their specific obligations differ based on whether they store or process the data.
Why Are Data Holders and Data Recipients Important in Open Banking?
In the context of open banking, data holders and data recipients are critical players in driving innovation and giving consumers control over their own data. By enabling the secure sharing of consumer data, the system fosters transparency and competition in the financial sector, leading to better services and products for consumers.
Benefits for Consumers:
- Greater Control: Consumers can decide who has access to their data and for what purpose.
- Enhanced Services: Data recipients can offer more personalised and relevant services, such as tailored financial advice, based on real-time data.
- Transparency: Open banking ensures that consumers know exactly how their data is being used, providing greater peace of mind.
How Does Fiskil Fit into the Picture?
When it comes to accessing consumer data securely and efficiently, Fiskil plays an essential role. Fiskil provides a platform that connects businesses with real-time banking and energy data, enabling both data holders and recipients to operate seamlessly under the CDR framework.
How Fiskil Supports Data Holders and Data Recipients:
Secure Data Access: Fiskil’s infrastructure ensures that data holders can share consumer data securely with accredited data recipients, all while complying with regulatory standards.
Real-Time Data Integration: Fiskil’s APIs offer real-time access to consumer data, enhancing decision-making and improving the delivery of personalised services for consumers.
Compliance-Ready Solutions: Fiskil’s pre-built compliance solutions ensure that businesses can meet their obligations under the CDR framework, GDPR, and other regulatory requirements without incurring significant development costs.
Fraud Detection: Fiskil leverages data to help businesses detect and prevent fraudulent activities, ensuring that both data holders and recipients maintain high levels of security and trust.
With Fiskil, businesses can streamline their operations, reduce risks, and enhance customer experiences by leveraging the power of real-time consumer data. For more information on how Fiskil can support your business, visit the Fiskil website.
Conclusion
The roles of data holders and data recipients are foundational to the success of open banking and the broader consumer data ecosystem. Data holders manage and secure the data, while data recipients leverage it to offer personalised services, all with the consumer's consent. Understanding the difference between these two entities is crucial for navigating the world of open banking, ensuring compliance, and delivering better services to consumers.
By working with platforms like Fiskil, businesses can simplify the process of accessing and sharing consumer data while ensuring compliance with regulatory frameworks like the CDR and GDPR. Fiskil offers secure, real-time data access solutions that empower businesses to improve their services, reduce risks, and meet their regulatory obligations.
Relevant Links:
Fiskil Resources
- Fiskil Official Website
- Fiskil Blog
- Consumer Data Right
- EU Data Act: What is a Data Holder?
- Data Holder Solutions for Banks: CDR
- Cost of Data Holder Services: What to Expect
- Accredited Data Recipients
Insights on Consumer Data Right and Data Holders
- OAIC: Consumer Data Right Participants
- CDR: For Providers
- Frollo: Consumer Data Right Support
- OAIC: Privacy FAQs for Accredited Data Recipients
- Cloudentity: Consumer Data Right Overview
- CDR: Compliance Requirements for Data Holders
- CDR Support: Brands in the CDR Ecosystem
- CDR Support: Brands in the CDR Ecosystem (Alternate Link)