Contact us

Australian Consumer Data Right Policy

Date of last review and update: 25 June 2026

Abstract

Being transparent with our customers and keeping you informed are essential parts of our business. As the Consumer Data Right legislation requires, we’ve put together this Australian Consumer Data Right (CDR) Policy. This policy explains how we manage your CDR data, with whom your data is disclosed, and how to lodge a complaint if needed.

 

Scope

As an Accredited Data Recipient (ADR), SISS Data Services (SDS) provides a secure platform for software applications (apps) to access data under the Australian Consumer Data Right (CDR). If you’re familiar with the concept of ‘open banking,’ you likely understand what the CDR entails. As a data business, SDS is certified to ISO 27001 and maintains robust security controls to always protect your data.

This CDR policy covers all SISS Data Services products and services that operate under the Australian Consumer Data Right (CDR) framework.

 

ACSISS My Data

SISS Data Services (SDS) has developed its own web application, “ACSISS My Data,” which enables consumers to share banking data with their nominated Trusted Adviser(s) or third-party applications, including systems used for accounting, administration, lending and other purposes. The third party and purpose for which data will be shared is disclosed to the consumer as part of the consent process, and data is only shared where the consumer has agreed.

More importantly, the My Data web portal gives consumers a transparent view of their data and functions to manage it. The key functions of the ACSISS MyData portal are as follows.

  • List of consents and the Banks with whom the consumer has consented, including the date and period of consent.
  • Accounts that have been selected during the consent process.
  • Transactions that have been collected for each bank account.
  • List of Trusted Advisers (like an Accountant or Bookkeeper) with whom the consumer has shared data, including the period of access and list of shared bank accounts. Consumers can modify or withdraw a share at any time.
  • List of third-party applications (like accounting software), including the period of access and list of bank accounts. Consumers can modify or withdraw a share at any time.
  • Notifications of key events like collection or non-collection of data, expiry of consents, and many more.

Trusted advisers and third-party applications operate independently of SDS. SDS does not control their systems, security practices, or data retention once data is disclosed under a valid consent.

 

CDR Ready

SISS Data Services also operates CDR Ready (www.cdrready.com.au), a self-service tool that allows individuals and business consumers to test their CDR readiness. Consumers grant a one-off, short-duration consent with their nominated bank(s) to verify that their accounts and permissions are correctly configured for data sharing under the Consumer Data Right. Where a consent does not complete successfully, CDR Ready provides consumers with guidance on likely causes and steps to resolve them.

 

Data Collection and Use

Collection of your CDR data

We are seeking (with your consent) to collect specific data your bank can provide. It’s important to note that SDS does not collect additional data, such as voluntary consumer data, that the bank may have but is not obligated to supply under the CDR rules. With your consent, we will collect and provide data to your nominated trusted adviser or third-party application. There are no costs for the consumer to consent or collect CDR data. The following is an example of data that could be collected,

  • Account Details, including a balance
  • Transaction details
  • Name & Contact Details

Please note that the primary use of our solution is to provide bank data to a consumer-nominated trusted adviser or third-party applications; therefore, the account details and transactions must be shared for this solution to be effective.

Data collection could occur on a single occasion or over a period. The consent period will be disclosed in the consent and, in most cases, will be for the maximum allowed period of 12 months (365 days). The consent period is displayed within the consent dashboard within the ACSISS My Data portal.

When the consent is for a period, the SDS platform will connect and collect data from your bank several times daily. Data collection is automated and does not require any consumer involvement.

When SDS holds a disclosure consent with a Trusted Adviser or third-party application, that party can only receive data during the sharing period disclosed to the consumer during the consent journey. When a collection consent ends, SDS can no longer collect new CDR data from the relevant Data Holder under that consent. When a disclosure consent ends, the relevant Trusted Adviser or third-party application can no longer receive further data under that consent. Ending a disclosure consent does not necessarily end a separate collection consent held by SDS.

 

Purposes of CDR data

SDS collects, holds, and uses CDR data for the following purposes:

  • to establish, manage, and maintain consumer consents and data sharing arrangements;
  • to enable consumers to share their data with nominated trusted advisers or third-party applications;
  • to provide data enrichment and processing from our outsourced service providers when disclosed in the consent journey; 
  • to provide, operate, and maintain SDS systems and services;
  • to ensure data quality, integrity, and system functionality;
  • to provide customer support and respond to enquiries or complaints;
  • to investigate incidents, errors, or suspected breaches;
  • to comply with legal and regulatory obligations, including the Consumer Data Right Rules.

SDS does not use CDR data for marketing or unrelated commercial purposes. 

 

Use of Artificial Intelligence

SDS may use software tools that incorporate artificial intelligence (AI) capabilities to support internal business operations such as software development, testing, product research, and customer support assistance.

These tools are not used to access, process, analyse, or derive insights from CDR data. 

CDR data is not used to train AI models or for other secondary AI analytics. Any data enrichment or risk scoring is performed only to provide the service disclosed in the relevant consent journey. 

Access to CDR data remains restricted to controlled environments and authorised personnel in accordance with this policy. 

 

Consumer Control

Withdrawing Consent

Consumers can withdraw consent at any time via the following methods:

  • ACSISS My Data portal and using the consent dashboard; or
  • Data Holder (Bank) and using their consent dashboard; this may be available via their mobile app or their browser-based site or
  • in writing (email or post) to SDS or the Bank(s).

The withdrawal of consent via a dashboard (ACSISS or Bank) will be immediate. Withdrawal via a dashboard will ensure both parties (SDS & Bank) will invalidate the consent; there is no need to withdraw a consent from SDS and Bank, the CDR specifications require each party to communicate the consumer’s withdrawal. If consent is withdrawn via writing, it may take two business days to finalise after it is received.

The effect of withdrawal depends on the type of consent withdrawn. Withdrawing a collection consent stops SDS from collecting new CDR data under that consent. Withdrawing a disclosure consent stops the relevant Trusted Adviser or third-party application from receiving further data under that consent. Withdrawal does not reverse data already disclosed before the consent ended.

 

Correction of data

If a consumer notices errors in the data held by SDS, they have the right to request a correction. They can do this by contacting us using the methods mentioned in this policy.

As SDS collects data, it may be more prudent for consumers to contact Data Holders directly, as they also have the obligation to correct the source data. Correcting the source data will allow SDS to collect the corrected data.

When requesting a correction, provide specific details so we can assess the issue and contact the proper data holders. SDS will action correction requests within 10 business days of receiving your request. If your correction request relates to data that has been processed or enriched by one of our outsourced service providers, SISS will manage that request on your behalf. As the accredited data recipient, SDS remains responsible for compliance with its obligations under the Consumer Data Right in relation to services performed by an outsourced service provider on SDS’s behalf. Where a correction requires updated data to be sourced from the Data Holder, this timeframe is subject to the Data Holder’s own processes and response times, which are outside SDS’s control. After the correction, we will contact you to notify you of the correction and details of the changes. If we determine that a correction is unnecessary or inappropriate, we will notify you of the reasons and explain your options to seek a review or make a complaint. 

 

Data Management

Disclosure of consumer data

SDS only discloses CDR data where:
• the consumer has provided express consent (e.g. to a trusted adviser or third-party application); or
• SDS is required or authorised to do so under law, including the Consumer Data Right Rules.

SDS does not disclose CDR data for marketing, advertising, or unrelated commercial purposes.

SDS personnel may access CDR data where necessary to:
• operate and maintain SDS systems;
• provide customer support;
• ensure data quality; or
• investigate incidents or complaints.

All such access is controlled, logged, and limited to authorised personnel. 

 

Outsourced service providers (OSP)

SDS may engage outsourced service providers to perform specified services using CDR data on SDS’s behalf. Where an outsourced service provider is involved in a service, SDS will disclose that role in the relevant consumer journey. Outsourced service providers act on behalf of SDS and do not receive your data as independent recipients. 

The outsourced service providers SDS may engage and the services they provide are set out below. 

Walker Street Data (WSD) 

Walker Street Data Pty Ltd (ABN 74 686 165 711) is engaged only for services and consumer journeys in which SDS has disclosed its involvement. In those cases, SDS will provide the data described below to Walker Street Data for the purposes disclosed to the consumer. 

Walker Street Data acts strictly as an outsourced service provider on behalf of SDS. It does not receive data as an independent recipient and cannot use data for its own purposes. 

 

Services provided: 

Data enrichment, including transaction categorisation, merchant identification and risk scoring 

Classes of data: 

Bank transaction data, account details and limited business information, including the businesses’ ABN. 

Data minimisation: 

SISS provides Walker Street Data with the data necessary to perform enrichment services. This includes business transaction data, account details (including account name, account type, BSB, account number and bank name), and the Australian Business Number (ABN) associated with the business consumer. Consumers are identified within the enrichment process via a unique customer identifier. 

Disclosure method: 

SDS securely transmits the data described above to Walker Street Data via API for enrichment and retrieves the enriched results directly from Walker Street Data. Walker Street Data does not have access to SDS systems or the SDS CDR environment. 

Location: 

Australia 

Accreditation status: 

Walker Street Data is not an accredited data recipient. It is engaged by SISS as an outsourced service provider under a CDR outsourcing arrangement in accordance with Rule 1.10 of the CDR Rules. SISS remains responsible for compliance with its CDR obligations in relation to that arrangement. 

Data retention and deletion: 

Walker Street Data must not retain service data longer than required to perform the services for SDS and must handle deletion in accordance with SDS instructions and applicable CDR obligations. 

Further information: 

For information on how Walker Street Data handles data, see https://www.walkerstdata.com.au/. 

 

Service Providers

SDS uses selected service providers to support the operation of its CDR services. These providers may host, store, or process CDR data on behalf of SDS for limited operational purposes such as infrastructure hosting, data storage, backup, and system availability.

SDS maintains strict controls over all service providers, including contractual, security, and access controls, to ensure CDR data is handled in accordance with the Consumer Data Right Rules and applicable privacy laws.

SDS does not disclose CDR data to third parties for marketing, analytics, or unrelated commercial purposes.

The following service providers are currently used:

Microsoft Azure
Used to host SDS applications, databases, and backup systems. This includes storage and processing of CDR data on SDS’s behalf.
• Primary region: Australia East (Sydney)
• Secondary region (disaster recovery): Australia Southeast (Melbourne)

SDS stores CDR data in Australia and does not currently store CDR data outside Australia.

SDS holds CDR data in secure cloud-based systems with encryption, access controls, and monitoring aligned to industry standards. SDS ensures that all CDR data remains subject to SDS control and is not used by service providers for their own purposes. 

 

Data Deletion

SDS applies a data minimisation approach and deletes CDR data once it is no longer required. SDS elects to delete data by default and does not offer de-identification.
CDR data becomes redundant when the relevant consumer consent is withdrawn or expires.

Consumers are not required to take any action for deletion to occur, as deletion is automatically triggered when data becomes redundant.

When CDR data becomes redundant, SDS will delete the data in accordance with the Consumer Data Right Rules. Deletion is initiated promptly once CDR data becomes redundant and is typically completed within minutes, subject to system availability and operational constraints.

Deletion occurs through controlled processes within SDS systems. Following deletion:
• SDS will no longer hold the data in active systems; and
• SDS will no longer be able to disclose that data.

 

Backup systems

CDR data may continue to exist in secure, encrypted backups for a limited period. These backups:
• are not accessible in normal business operations and are only accessed under controlled conditions for disaster recovery purposes;
• are maintained for system recovery and resilience purposes only; and
• are automatically overwritten or deleted in accordance with SDS retention schedules (up to two years).

SDS retains limited operational metadata related to consents. This metadata does not include CDR data sourced from a data holder and is retained solely to meet regulatory obligations, support investigations, and maintain system integrity.

If CDR data has been disclosed to a trusted adviser or third-party application, SDS does not control their retention or deletion practices. Consumers should contact those parties directly. 

Please note that where a service relies on ongoing access to your banking data, withdrawing your consent may affect the availability or functionality of that service. SDS will cease data collection immediately upon withdrawal but cannot reverse disclosures already made under the prior consent. 

 

Communications and Notifications

Consent notifications

Consumers will receive a 90-day notification by email, which will also be available in the ACSISS My Data portal. Notifications confirm the data holder (bank), expiration date, selected bank accounts, and data types shared.

SDS notifies consumers prior to consent expiry as a courtesy reminder, and again upon expiry confirming that the consent has ended and data collection has ceased.

 

Mandatory CDR Communications

Certain communications about your participation in the Consumer Data Right (CDR) are mandatory under Australian law. These include notifications such as periodic 90-day confirmation of consent, data sharing disclosures, revocation confirmations, and related system alerts.

Under the CDR Rules (Competition and Consumer Act 2010, Part IVD) and associated Consumer Experience (CX) Guidelines, these communications are required to:
• Confirm the creation or withdrawal of your data-sharing consent,
• Provide transparency over how your data is used or disclosed, and
• Maintain legal accountability across the CDR ecosystem.

These messages are not promotional and are not subject to unsubscribe options. They are a condition of participating in services that operate under the CDR framework.

If you have concerns about any message you’ve received, please get in touch with us at help@siss.com.au.

 

Incidents & Disputes

Data Security Incidents

SDS takes data security seriously and has processes in place to respond to actual or suspected data security incidents.

In the event of an incident, SDS will:
1. Investigate – assess the nature and scope of the incident
2. Contain – take steps to limit further impact
3. Assess – determine whether the incident is likely to result in harm
4. Notify – notify affected individuals and regulators where required under applicable laws, including the Notifiable Data Breaches scheme
5. Remediate – address the cause of the incident
6. Monitor – ensure controls are effective
7. Review – identify improvements to prevent recurrence

 

 

Complaints and Disputes Overview

How to make a complaint
SDS takes our legal obligations seriously. However, we also believe the consumer experience is just as important. After all, this is the “consumer” data, right, so we would like to extend the opportunity to consumers and their Trusted Advisers to contact us if they believe anything is unsatisfactory, be it data quality, a suspected cybersecurity incident, a privacy concern, or a breach of CDR rules and regulations.

SDS intends to handle a complaint or dispute professionally and promptly. SDS has both an internal and external dispute resolution service to enable this. The following section details our internal complaints process. Our external process is via the Australian Financial Complaints Authority (AFCA), and the process is detailed below.

Who may complain?

Anyone utilising our solution, be that a consumer with a My Data user account or a partner (trusted adviser or third-party application), utilising our platform.

 How to complain?
To start this process, use one of the methods in the Contact Us section. We prefer email, as this lets you provide us with as much detail and context as possible. Please do not hesitate to attach files as evidence or documentation for us to assess to and use with our investigations.

We have a specific email address you may use for complaints: complaints@siss.com.au. Please include the following information when submitting your complaint.
• Your name;
• If lodging on behalf of another person, please provide enough detail so that we may identify their data. The email address used when registering with ACSISS My Data is a key identifier for us.
• Your contact details.
• Your preferred contact method (phone, email or letter); and,
• The details of your complaint.

Complaints will first be reviewed using our internal dispute resolution process. After receipt, our compliance officer will manage the investigation, supported by our support team.

What are the timeframes?

A complaint can be made at any time. Once your complaint is received, SDS will acknowledge receipt within two (2) business days. SDS will investigate your complaint and attempt to provide you with a written response to resolve it within thirty (30) calendar days. Should there be reasons why this cannot be achieved, we will notify you of the reasons and estimated timelines. While investigating, we may need to liaise with other parties like banks, trusted advisers, or third-party applications.

When the complaint is resolved, you will receive a ‘final response’ letter within thirty (30) calendar days of receipt of your complaint, informing you of:

  • the outcome of your complaint 
  • your right to make a complaint to an External Dispute Resolution service 
  • your right to ask us to review our response if you believe it is unsatisfactory 
  • your right to contact the Australian Financial Complaints Authority (SDS is a member as required by the accreditation rules) 

If your complaint remains outstanding after thirty (30) calendar days, SDS must write to you to: 

  •  inform you of the reasons for the delay
  • specify a date when a decision can be reasonably expected 
  • inform you of your right to take your complaint or dispute to an External Dispute Resolution service
  • advise that you may complain to the Australian Financial Complaints Authority if dissatisfied.

 

External Dispute Resolution

Customers can refer a complaint to our external dispute resolution service. It should be noted that AFCA is an independent body with its own processes and assessments when handling complaints. As our CDR accreditation requires, SISS Data Services is an AFCA member (number 74025).

Australian Financial Complaints Authority (AFCA)
• [Web] www.afca.org.au
• [Email] info@afca.org.au
• [Phone] 1800 931 678 (free call)
• [Mail] GPO Box 3, Melbourne VIC 3001 

Office of the Australian Information Commissioner (OAIC)
Consumers may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) where the complaint relates to the handling of CDR data or privacy matters.
• [Web] www.oaic.gov.au
• [Email] enquiries@oaic.gov.au
• [Phone] 1300 363 992
• [Mail] GPO Box 5218, Sydney NSW 2001 

 

Closing

Contacting Us

You can contact us anytime via
• Email (general enquiries): help@siss.com.au
• Email (complaints): complaints@siss.com.au
• Phone: 02 9299 4547 (NSW business hours)
• Post: SISS Data Services, PO Box 98, Crows Nest NSW 2065
• Website: www.acsiss.com.au/contact-us/
Once we receive your contact information, we will respond as soon as possible. 

 

Summary of Participants in CDR system

  • CDR: Consumer Data Right gives you the right to share your data between service providers of your choosing. It is active in banking and energy. This policy relates to SDS’s banking services: https://www.cdr.gov.au/
  • Consumer: This is you the person or business seeking to have their data collected from a data holder and delivered to a software application
  • Business Consumer: Under the CDR Rules, a business consumer is a consumer acting in a business capacity rather than as an individual. SDS requires business consumers to provide a valid Australian Business Number (ABN) as part of onboarding and the consent process. SDS validates the ABN against official registers to confirm its active status. SDS requires the individual providing consent to confirm that they are authorised to act on behalf of the business associated with the ABN. The service is limited to business consumers with an active ABN.
  • Data Holder: This is the organisation that is the source of data, like a bank, that holds consumer data
  • Collection Consent: A consent given by a consumer that authorises SDS to collect CDR data from a nominated Data Holder (bank) on the consumer’s behalf. A collection consent defines the data types, accounts and period for which SDS may collect data. SDS can only collect CDR data while a valid collection consent is in place. 
  • Disclosure Consent: A consent given by a consumer that authorises SDS to disclose CDR data to a nominated third party, such as a Trusted Adviser or third-party application. A disclosure consent defines the recipient, the data to be shared and the period of sharing. Ending a disclosure consent stops further data being sent to that recipient but does not affect any separate collection consent SDS holds. 
  • Third-Party Application: A software solution or platform that a consumer uses to manage functions such as accounting, lending, administration or other purposes. Under the CDR, third-party applications are non-accredited parties. Data disclosed to a third-party application leaves the CDR regulatory framework and is handled by that party under their own practices and applicable privacy laws. 
  • Trusted Adviser: Under the Consumer Data Right is a specific defined set of professionals that a consumer may interact and have a relationship with, namely Accountants, Tax Agents, Lawyers, etc.
  • SDS: SISS Data Services operates a technology platform that enables data collection and sharing under the Consumer Data Right. In some arrangements within the CDR ecosystem, our platform may operate as outsourced service providers (OSPs) to another accredited data recipient. Under this policy, SDS is acting as an accredited data recipient (ADR) in its own right.
  • Outsourced Service Provider (OSP): An organisation engaged by SISS to provide specific services, such as data enrichment, where CDR data may be disclosed for that purpose. SISS may also act as an OSP for other accredited data recipients. In both cases, the OSP is bound by CDR obligations in respect of any service data handled, and SISS as the accredited data recipient retains responsibility for ensuring those obligations are met 
  • Risk Scoring: refers to the assessment of transaction data against predefined business rules and indicators to assist third-party applications in identifying potential financial or operational risks. 
  • ACCC: The lead Government regulator for the Consumer Data Right (CDR) system. ACCC is also responsible for the registration and compliance monitoring of ADRs. https://www.accc.gov.au/focus-areas/consumer-data-right-cdr-0
  • OAIC: Office of the Australian Information Commissioner. A government organisation with the purpose to uphold consumers’ rights to privacy and access to data utilising legislation such as the Privacy Act & Freedom of Information Act. https://www.oaic.gov.au/consumer-data-right/
  • ASIC: Australian Securities Investment Commission, a government organisation with the purpose of ensuring the proper function of corporations, markets, financial services and providing of credit. https://asic.gov.au/for-consumers/
  • AFCA: Australian Financial Complaints Authority are a dispute resolution service for consumers and organisations within the financial services industry. https://www.afca.org.au/