Consumer Data Right
What “Covered Products” Really Mean for Non-Bank Lenders Under CDR
What 'covered products' means under CDR for non-bank lenders. A compliance guide covering product scope, data obligations, and preparation steps before July 2026.
All Posts
Consumer Data Right
What 'covered products' means under CDR for non-bank lenders. A compliance guide covering product scope, data obligations, and preparation steps before July 2026.
CDR’s expansion into the non-bank lending sector has triggered one of the most common and persistent questions from lenders, product teams and compliance leaders:
What exactly counts as a “covered product”?
It sounds straightforward. It isn’t.
The confusion stems from three issues:
The ACCC’s latest guidance recognises this confusion and lays out how data holders in both banking and non-bank lending must assess whether a product is in scope. It centres on a clear three-factor test, supported by concrete examples across personal lending, business finance, asset finance, negotiated facilities, BNPL and more.
This guide breaks that guidance into a practical, compliance-ready workflow.
If you are a credit, legal, or product owner wondering:
Important note: ACCC guidance reflects current regulatory expectations but does not replace the legal effect of the CDR Rules or the Act.
For banking and non-bank lending, product scope is defined in:
Within this structure, “covered product” is the gatekeeper concept that determines whether required product and consumer data exists for a product at all.
Only after these steps do you progress to questions like:
To avoid talking past each other, here are the definitions that matter for compliance assessments.
Covered product
A product listed in Schedule 3, clause 1.4 and publicly offered and offered under a standard form contract.
If it fails any of the three elements, it is not a covered product.
Required product data
Non-consumer-specific information about the features, pricing, terms, eligibility and conditions of covered products. If a covered product falls into a mandatory category, required product data must be shared.
Required consumer data
Consumer-specific data for a covered product (e.g. balances, transactions, fees, repayments), provided the data holder actually holds that data for that product type.
Voluntary product and consumer data
Some covered products are designated as voluntary only under the Rules.
Meaning: even if a valid CDR request is made, the data holder is not required to disclose product or consumer data for that category.
Initial and large providers
A relevant non-bank lender only becomes a data holder with obligations when it meets the thresholds for initial or large provider status. This sits outside the covered product test but determines whether the entity must share data at all.
The ACCC is explicit: a banking or non-bank lending product is a covered product only if it meets all three criteria.
This is the precise mechanism that narrows the scope from “every lending product we offer” to “those products for which we must enable CDR data”.
The product must fall within one of the recognised product categories for the banking and non-bank lending sectors. Examples include:
If the product is not a type listed in clause 1.4, it is not a covered product. No further assessment is required.
Being listed does not automatically impose mandatory obligations. It simply means the product enters the “covered product” assessment.
The CDR Rules do not define when a product is considered “publicly offered”. However, the ACCC generally considers this criterion should be interpreted broadly.
A product is publicly offered if it:
Important clarifications from the guidance:
A product is usually not publicly offered if:
The ACCC guidance stresses that most banking and non-bank lending products available to consumers will satisfy this test.
This is the factor that generates the most debate across credit, legal and product teams.
Under the ACCC’s approach, a product is offered under a “standard form contract” where:
The ACCC points to section 27 of the Australian Consumer Law as the appropriate benchmark for interpreting this.
Minor negotiation on interest rates, credit limits, fees or standard options does not stop the contract being a standard form contract.
A product is likely not standard form if:
In other words: where negotiation extends beyond pricing and into core contractual rights and obligations, even if templates are reused.
Apply the factors in order:
If yes to all three: the product is a covered product.
If no to any factor: the product is not a covered product and CDR does not apply.
Only once a product is confirmed as a covered product should teams move on to determining:
Determining that a product is a covered product is only the first compliance step. The next question is whether sharing for that product is:
This distinction matters because several product categories in the banking and non-bank lending sectors are covered products but always voluntary.
Under Schedule 3 and the ACCC’s guidance, these categories are covered but voluntary for both product data and consumer data:
If a valid CDR request is made for these products, the data holder may respond but is not required to.
This is intentional. Treasury carved out these categories because they either:
“Asset finance” is listed as a covered product category in clause 1.4, but not all asset finance is equal under CDR.
Mandatory obligations apply only to:
Treasury’s policy intent is that CDR supports simple like-for-like switching for vehicle finance — not the entire asset finance ecosystem.
Examples include:
Where the asset finance product:
it typically fails the standard form contract test and therefore is not a covered product at all.
This is particularly relevant for:
Maintain a register categorising each product as:
| Product Type | Covered? | Mandatory or voluntary | Rationale |
|---|---|---|---|
| Consumer car loan | Yes | Mandatory | Listed category + publicly offered + standard form |
| SME unsecured loan | Yes | Mandatory | Business finance + standard terms + broad offer |
| Novated lease | Yes | Voluntary | Non-standard vehicle finance |
| Agricultural finance | Yes | Voluntary | Asset finance but not standard on-road vehicle finance |
| Invoice finance facility | Sometimes | Often out of scope | May not be publicly offered; often heavily negotiated |
| Structured investment loan | No | N/A | Not publicly offered and not standard form |
| Warehouse / wholesale facility | No | N/A | Bespoke and negotiated |
This record becomes part of the organisation’s defensible compliance position and is essential for audit readiness.
The CDR Rules include a deliberate carve-out for trial products, recognising that some lenders need to test a product in market before being required to expose that product through CDR APIs.
A covered product is a trial product if it meets all of the following criteria:
If a product meets these criteria, CDR obligations do not apply to it while the trial is underway.
This means:
A trial product becomes an in-scope covered product the moment:
Once this occurs:
Trial products mean:
This is one of the reasons why robust API infrastructure like Fiskil’s Data Provider is beneficial — it makes the flip from voluntary to mandatory operationally consistent.
The ACCC guidance clarifies categories that are typically out of scope altogether, even if they look like lending products at first glance.
These products fail the test for one or more of:
These often fail both factor 2 (publicly offered) and factor 3 (standard form contract).
Examples:
These products are not marketed broadly, involve material negotiation, and are built around a customer-specific credit profile.
Even if individual sub-products under a multi-option facility resemble standard products (e.g., overdrafts or lines of credit), the umbrella facility:
Therefore, the facility as a whole is not a covered product.
If a financial institution manufactures a facility exclusively for a partner brand, and that facility is:
then the underlying product may fall out of scope even if consumers use it.
Some invoice finance is standardised and broadly marketed (covered products), while others are tailored, negotiated, relationship-only products (out of scope).
This underscores the need for product-by-product assessment, not a blanket category rule.
Because many product categories sit in a grey zone — particularly in business and asset finance — lenders must:
Your covered product register is a living compliance artefact, not a one-time classification exercise.
Understanding whether a product is a covered product is one side of the compliance equation. The other is whether your organisation is actually a data holder with obligations.
For non-bank lenders, obligations apply only to entities that meet the definition of:
as defined in the CDR Rules and the May 2025 non-bank lender fact sheet.
A lender may offer a covered product, but if it is not an initial or large provider, it has no mandatory obligations to share data for that product.
A relevant non-bank lender is an initial provider if it met the following criteria on 4 March 2025:
If a lender did not meet these criteria on that date, it will never become an initial provider.
A relevant non-bank lender becomes a large provider if, on 4 March 2025 or any 1 July thereafter:
Once a lender becomes a large provider, it remains one permanently unless it ceases to be a relevant non-bank lender.
An entity may meet the criteria to be an initial or large provider yet:
for the products it offers.
In these cases, although the entity is an initial or large provider, it is not expected to meet data sharing obligations until it actually holds in-scope data.
This often applies to entities offering:
Even if not required, a relevant non-bank lender may choose to participate voluntarily. Once it does, it must comply with all applicable CDR Rules and Standards.
Once a lender has:
it must make the product accessible to eligible CDR consumers via the prescribed data sharing channels.
A data holder must provide an accredited data recipient with a way to request consumer data on behalf of a CDR consumer. This includes:
Product data must also be made discoverable via the Product Reference Data APIs.
For mandatory categories:
For voluntary categories:
Data holders must ensure:
Voluntary participation is not a lighter regulatory path.
For now, non-bank lenders do not have obligations to respond to “complex requests”.
A request is “complex” if it:
The Rules exclude complex requests for initial and large providers in the non-bank lender sector.
This carve-out may be revisited in future rule-making phases.
To streamline decision-making, adopt a repeatable assessment workflow aligned with ACCC guidance.
For each product, determine:
If “yes” to all three: covered product.
If “no” at any stage: out of scope.
Check whether the product is:
If yes: covered but voluntary only.
For products labelled “pilot” or “trial”, monitor:
Only when thresholds are exceeded do obligations switch on.
Confirm whether your organisation is:
If neither: no mandatory obligations apply.
Even if the product is covered:
For each product:
Reassess whenever:
Incorrect.
Business finance products are expressly listed in clause 1.4. If they are publicly offered and offered under largely standard terms, they are covered products.
Incorrect.
Minor negotiation (interest rates, fees, standard variations) does not remove the product from scope. The test is whether the contract is materially negotiated.
Incorrect.
Only standard consumer vehicle finance is intended to be mandatory. Much asset finance is covered but voluntary, and heavily negotiated asset finance often falls out of scope.
Incorrect.
Bespoke products are usually out of scope, not voluntary. Voluntary applies only to products that are covered but designated as voluntary in the Rules.
Incorrect.
BNPL is explicitly listed as a product category. Mandatory dates vary, but BNPL is part of the designated product set for non-bank lenders.
Incorrect.
If you hold no required consumer or product data for that product type, you are not expected to meet data holder obligations until you do.
The concept of a “covered product” is not something lenders can determine once and forget.
Product portfolios evolve, new variations emerge, and distribution channels change. What is out of scope today may be in scope six months from now — particularly as:
A robust CDR compliance framework treats the covered product assessment as a living artefact, reviewed regularly and shared across product, compliance, risk, engineering and legal functions.
At the same time, comprehensive and stable API infrastructure is essential. A data holder must be confident that when a product moves from out-of-scope to in-scope (or from voluntary to mandatory) the technical capability is already in place to support secure, standards-aligned data sharing.
This is where platforms like Fiskil’s Data Provider make a measurable difference.
A modern, high-performance data sharing layer ensures:
The result is a compliance posture that is not just defensible, but operationally resilient — and a data sharing experience that strengthens consumer trust and positions your organisation for the next phase of open data innovation.
Build with Fiskil
Whether you need to access consented financial data or share data to meet compliance obligations, Fiskil gives you the APIs and infrastructure to do it.

CDR for Non-Bank Lenders: A Transformation, Not Just Compliance
How CDR obligations reshape non-bank lenders from July 2026. Product data, consent management, and compliance requirements for NBLs entering the Consumer Data Right.

Using CDR Data to Streamline Customer Onboarding and KYC
In digital finance, customer onboarding and Know Your Customer (KYC) processes are more than compliance checkboxes, they’re your first impression. But some workflows still require the upload of PDF bank statements... in 2025.

Five Years of the CDR: What We've Learned and What’s Next
Five years since Australia launched the Consumer Data Right. Key milestones, lessons learned, adoption stats, and what's next for CDR in banking, energy, and beyond.