The accreditation hierarchy
There are three roles you may encounter inside the CDR ecosystem:
- Data Holder: the bank, energy retailer, or telco that holds the consumer data and must expose CDR APIs. All Australian Authorised Deposit-taking Institutions are required to be Data Holders.
- Accredited Data Recipient (ADR): a business the ACCC has cleared to receive CDR data. Tiers exist (unrestricted, sponsored, etc.) with different obligations.
- CDR Representative: a business operating under an ADR's accreditation through a written principal agreement. The ADR remains responsible for compliance.
What ADR accreditation requires
- An information-security regime aligned with ISO 27001 (or equivalent).
- An external assurance report on the security regime.
- Insurance arrangements covering CDR-data risks.
- A board-approved CDR Policy published on the recipient's website.
- Demonstrated governance and complaints-handling processes.
- Ongoing compliance reporting to the ACCC.
How to verify any CDR provider
- Visit cdr.gov.au/find-a-provider.
- Search the provider name.
- Confirm accreditation status, number (e.g. ADRBNK000246), and effective dates.
- Check for any conditions, suspensions, or revocations on the listing.
- For Representatives, confirm the parent ADR is also active.
Why this matters
Tools that claim to use "open banking" or imply CDR-grade compliance without accreditation should not be allowed near your bank credentials. Screen-scraping tools fall outside this framework entirely. If you cannot find a provider on the public register, it is not accredited.