Quick answer
Open banking in Australia runs under the Consumer Data Right. It lets you direct your bank to share your data with an accredited provider — such as a service a lender uses — for a stated purpose. The OAIC says consent expires after 12 months, you can stop sharing at any time, and you get a dashboard to manage it. For a business loan, it means verified bank data in minutes.
Key points
- CDR data sharing in banking has been live since 1 July 2020
- Only accredited providers can receive CDR data
- Consent expires after 12 months and can be withdrawn at any time
- You manage what you've shared through a consumer dashboard
- Framework
- Consumer Data Right (CDR)
- Consent lasts
- Up to 12 months
- Stop sharing
- Any time, via dashboard
What does open banking mean for a business loan?
Open banking lets you tell your bank to share your account data with another organisation you choose, for a purpose you agree to. In Australia it runs under the Consumer Data Right, usually shortened to CDR. For a business loan, it means a lender — or a service the lender uses — can receive verified transaction data straight from your bank, rather than waiting for you to download and send statements.
The practical upside is speed and accuracy. The practical question most owners ask is: what exactly am I agreeing to? This page answers that.
How does the Consumer Data Right work?
The ACCC describes the CDR as a way for consumers to safely share the data that businesses hold about them. A few points matter most:
- Banking has been live since 1 July 2020, and the ACCC says all Australian banks are required to participate.
- Only accredited providers can receive the data. The ACCC manages accreditation.
- You opt in. Nothing is shared unless you give consent through the process.
- Consent has limits. The OAIC says consent to use your CDR data expires after 12 months.
- You can stop at any time, and each provider must give you an online dashboard to manage your CDR activity.
- You can ask for deletion of your data once it’s no longer needed.
That combination — accreditation, time-limited consent and a dashboard — is what distinguishes CDR sharing from simply emailing someone your statements.
What happens when you consent?
The flow usually looks like this:
- The lender or its data partner asks for consent, explaining what data it wants, why and for how long.
- You’re redirected to your own bank to authenticate. You log in with your bank, not with the recipient.
- You choose the accounts to share and confirm.
- The data arrives with the accredited recipient, who uses it for the purpose you agreed — here, assessing your loan.
- You can review or stop sharing through the dashboard whenever you like.
For many businesses the whole thing takes a few minutes. If your bank or account type isn’t supported, other bank-statement link options or directly downloaded statements still work.
Want the benefit of faster data without doing the legwork alone? Start your enquiry and a specialist will tell you which sharing option suits your bank.
What should you check on the consent screen?
| Check | What to look for |
|---|---|
| Who receives the data | The accredited provider’s name, and the lender it’s working for |
| What data | Accounts, transactions, balances — only what’s needed |
| Why | The stated purpose, such as assessing a loan application |
| How long | A sharing period, within the 12-month maximum |
| After it ends | What happens to your data, and how to request deletion |
If any of those are unclear, ask before you proceed. A legitimate process will happily explain.
Is open banking safer than emailing statements?
In several ways, yes. Your banking password stays with your bank. The recipient is accredited. Sharing ends automatically, and you can end it sooner. Statement PDFs sent by email, by contrast, can sit in multiple inboxes for years, with no expiry and no dashboard.
That doesn’t mean you should share with anyone who asks. Check the business you’re dealing with, make sure the request is expected, and only follow links sent by the lender you’ve chosen.
An illustrative example
Illustrative only. A small online homewares retailer wants $30k unsecured to stock up before the Christmas peak. Her lender’s data partner asks for CDR consent to read her two business accounts for the purpose of assessing the application, with sharing set for a short period.
She’s redirected to her bank, logs in as normal, selects the two accounts and confirms. The retailer’s payment-platform settlements and supplier payments are all visible within minutes. After the loan is settled she checks her dashboard, sees the sharing arrangement, and stops it — well before it would have expired on its own.
What data does a lender actually receive through the CDR?
Only what you consent to share, and only from the accounts you select. For a business loan, that typically means transaction history, balances and basic account details for the business accounts involved. It doesn’t give the recipient the ability to move money, and your banking password stays with your bank.
It’s worth being deliberate about which accounts you include. Share the main trading account and any account where customer payments or card settlements land. If you have a separate tax savings account, including it can actually help — it shows money is being set aside for BAS. Personal accounts generally don’t need to be shared for a business loan unless the lender specifically asks, for example where a sole trader runs everything through one account.
After the loan is decided, check your dashboard. If the sharing period is longer than you need, you can stop it. The OAIC also notes you can ask for your data to be deleted once it’s no longer needed. Knowing where that dashboard is, and using it, is part of sharing data sensibly.
Ready to share smarter?
Open banking can take days out of a loan, but only once you’re on the right pathway. Start with the 60-second enquiry. There’s no credit check when you first enquire, your details stay with one specialist rather than a mailing list of lenders, and a real person will explain exactly what data your loan needs and why. Accurate answers on the form mean the data you share later simply confirms what you told us.
Frequently asked questions
What is open banking in Australia?
It's the banking part of the Consumer Data Right. It lets you direct your bank to share data it holds about you with an accredited provider, for a purpose you consent to. The ACCC says live sharing in banking began on 1 July 2020 and all Australian banks must participate.
How long does my consent last?
The OAIC says consent to use your CDR data expires after 12 months. You can stop sharing earlier at any time.
How do I stop sharing my bank data?
Through the consumer dashboard the provider must give you, or through your bank. The OAIC notes you can stop sharing at any time and ask for your data to be deleted once it's no longer needed.
Does open banking give the lender my password?
No. You authenticate with your own bank, which then shares the data you've consented to. Your banking password isn't handed to the recipient.
Is every bank-statement service part of the CDR?
No. Some bank-statement services work outside the CDR framework. Read the consent screen so you know which kind you're using and what protections apply.