What Is a Data Holder in CDR?
Discover the role of data holders in Australia's CDR framework, ensuring secure, compliant data sharing and empowering consumers with control.
With the advent of the Consumer Data Right (CDR) in Australia, understanding the roles of key participants in this ecosystem has become crucial. One such role is that of a data holder. Data holders are pivotal to the secure and compliant sharing of consumer data in the open banking system, empowering consumers with control over their personal information. This article will define what a data holder is, outline its responsibilities, and explore its role in the CDR framework.
For a broader understanding of the CDR framework, you can visit the official CDR website.
What Is a Data Holder?
A data holder is a business or financial institution that holds consumer data and is legally obligated to share it with authorised third parties when the consumer gives their explicit consent. In the Australian context, the four major banks—Commonwealth Bank, Westpac, ANZ, and NAB—are examples of data holders, particularly under the open banking system. Many other banks and financial institutions have also become data holders as part of the CDR.
The primary role of a data holder is to manage and safeguard consumer data while allowing accredited data recipients to access that data, provided that the consumer has authorised the sharing. Data holders must comply with stringent privacy and security regulations to ensure the safe transfer of data. For more details on the compliance responsibilities of data holders, refer to this guide on data holder compliance.
Responsibilities of a Data Holder in CDR
Data holders are integral to the data-sharing ecosystem. They have specific responsibilities under the CDR framework, which are designed to protect consumer rights while fostering innovation in the financial services industry.
1. Data Management and Protection
Data holders must ensure the security and accuracy of consumer data. Implementing robust cybersecurity measures is crucial to protect consumer data from unauthorised access or breaches. For example, a bank might use data encryption techniques to safeguard consumer information. You can find more information on cybersecurity requirements for data holders on the ACCC’s website.
2. Facilitating Data Sharing
When a consumer requests data sharing with an accredited data recipient, the data holder is required to securely transmit the data. This process must follow stringent security protocols, ensuring data safety. Learn more about data sharing obligations.
3. Ensuring Compliance with Regulations
Data holders must comply with the guidelines set by the Consumer Data Right (CDR) and the Privacy Act. Compliance involves ensuring the secure transfer of data while respecting consumer consent and privacy. Visit the Australian Competition and Consumer Commission (ACCC) for details on CDR regulations.
How Do Data Holders Ensure Compliance with CDR Regulations?
Ensuring compliance with CDR regulations is a critical responsibility for data holders. The CDR framework imposes strict obligations to protect consumers' rights, enhance data security, and foster transparency in the use of personal information. Below are key measures data holders must take to stay compliant with CDR regulations:
1. Consent Management
- One of the primary compliance requirements is obtaining explicit consumer consent before sharing any personal data. Data holders must implement transparent consent processes, ensuring consumers are fully aware of what data is shared, with whom, and for what purpose. Without this consent, data cannot be shared. For more details, refer to the OAIC guide on consent.
2. Data Security and Privacy Protocols
- Data holders must comply with robust privacy and security standards to safeguard consumer data. This includes measures like data encryption, access control, and regular audits to prevent unauthorised access or breaches.
3. Accreditation Verification
- Before sharing any data, data holders must ensure that the recipient is an accredited data recipient under the CDR framework. Accreditation ensures that the recipient has met all the legal and security standards necessary to handle sensitive data responsibly. Visit the ACCC CDR accreditation register for more information on accredited recipients.
4. Compliance Audits and Reporting
- Data holders are required to conduct regular audits of their data-sharing processes and report any breaches or non-compliance issues to regulatory bodies such as the Office of the Australian Information Commissioner (OAIC). For detailed reporting requirements, check out the OAIC’s CDR overview.
How Data Holders Benefit Consumers

Data holders play a key role in empowering consumers with greater control over their personal information. By facilitating secure data sharing, they enable consumers to access tailored services, better financial products, and improved customer experiences.
1. Enhanced Consumer Choice
- With data holders enabling data sharing, consumers can access more competitive products and services. They can move their data across different platforms, choosing services that best meet their needs. Learn more about how CDR benefits consumers on Cuscal’s FAQ.
2. Personalised Financial Services
- Accredited data recipients can use the data provided by holders to offer personalised services, such as customised loan offers, financial management tools, and better budgeting systems.
3. Transparency and Trust
- Data holders must provide clear information to consumers about how their data will be used and ensure that they have full control over their personal information. This transparency fosters trust between consumers and financial institutions.
Fiskil: Enhancing Data Management in the CDR Ecosystem
When it comes to managing and sharing data securely within the CDR framework, Fiskil plays a vital role. Fiskil is a technology platform that helps both data holders and data recipients manage their data-sharing obligations efficiently and securely.
What Fiskil Does
- Fiskil simplifies the process of accessing real-time banking and energy data under the CDR. By managing the complexities of data sharing, Fiskil enables companies to focus on their core business while ensuring compliance with legal obligations.
Fiskil’s Compliance Solutions
- Fiskil’s APIs are designed to help businesses meet their compliance obligations under the CDR and other regulatory frameworks. For more details, visit the Fiskil website.
Conclusion
In the CDR ecosystem, data holders play a crucial role in managing, securing, and sharing consumer data. Their responsibilities, from data protection to ensuring compliance with regulatory frameworks, are fundamental to the success of open banking. Platforms like Fiskil enhance this process by offering streamlined, secure solutions for data management and sharing. With Fiskil’s technology, both data holders and data recipients can confidently navigate the complexities of the CDR framework, ensuring compliance while delivering better services to consumers.
Relevant Links:
Fiskil Resources
- Fiskil Official Website
- Fiskil Blog
- EU Data Act: What is a Data Holder?
- Data Holder Solutions for Banks: CDR
- Cost of Data Holder Services: What to Expect
- Accredited Data Recipient
- Consumer Data Right
- NAB API Landscape