What happens at expiry
When a consent expires, the Accredited Data Recipient (or its CDR Representative) loses the right to fetch new data from the bank. The recipient's CDR Policy governs what happens to data already received. Common patterns:
- Data is retained but flagged read-only, in case you re-consent and want history continuity.
- Data is de-identified for analytics.
- Data is deleted in line with the policy and your account settings.
How to revoke early
You can revoke at any time, no questions asked, from either side:
- From your bank: every ADI must provide a CDR consent dashboard (look for "Data sharing" or "CDR" in your internet banking).
- From BankSync: open a connected bank in your dashboard and click "Revoke consent".
Both actions take effect immediately and propagate within minutes. The consent record remains in the audit trail for both you and the bank.