How CDR works in practice
When you connect a bank to BankSync, you are redirected to your bank's secure CDR authorisation page. You log in, choose what data to share (transactions, balances, etc.) and for how long (7 days, 90 days, or 12 months), and approve. Your bank issues a scoped access token to an Accredited Data Recipient (ADR). BankSync operates as a CDR Representative under Fiskil (ADR accreditation ADRBNK000246).
CDR vs screen-scraping
- Credentials: CDR never sees your password; screen-scraping requires you to share it.
- Scope: CDR consents are scoped to specific data types and durations; screen-scraping has unrestricted login access.
- Revocation: CDR consents are revocable from your bank or BankSync at any time; screen-scraping access ends only when you change your password.
- Regulation: CDR is supervised by the ACCC and Treasury; screen-scraping is not.
What data is shared
Only the scopes you authorise. Common ones include account details, balances, transactions, regular payments, and account-holder name. Sensitive data like credit reports is out of scope. You see exactly what is being shared at consent time and can review or revoke it anytime in your bank's CDR dashboard.
Which banks are covered
CDR is mandated for the entire Australian Authorised Deposit-taking Institution (ADI) sector — Big 4 banks, regional banks, neobanks, mutuals, credit unions, and brokerages with banking licences. The full register is at cdr.gov.au.