If you are a CTO or Head of Product in the lending or fintech space, you have likely watched the slow burn of the Consumer Data Right (CDR) rollout with a mix of curiosity and skepticism. For years, the industry has debated the merits of Open Banking versus the traditional method of screen scraping.
But as we move through 2026, that debate is effectively over.
The Australian Government’s recent “reset” of the CDR framework has signalled a shift from experimental compliance to operational necessity. With over 100 accredited data recipients now active and major institutions like Commonwealth Bank aggressively moving away from legacy data sharing methods, the question is no longer if you should move to CDR, but how quickly you can do it before you experience a ‘loss of signal’.
This post explains why the tide has turned and why sticking with the status quo is now the riskier option.
The tide has turned on data sharing
For a long time, philosophising about the “potential” of Open Banking was easy. Early adoption was clunky, coverage was patchy, and the compliance burden felt heavy. However, the ecosystem has matured significantly – particularly around data quality and reliability.
2025 marked a tipping point due to the maturity of CDR and the systems supporting it. Customers now expect high quality data – highly reliable, highly accurate, and suitable for critical business processes.
The “Statutory Review of the Consumer Data Right” released in recent years also highlighted that while the initial rollout was complex, the foundational rails are now solid. We are seeing a distinct shift in consumer behaviour. Australians are becoming increasingly data-savvy, expecting secure, consent-based sharing rather than handing over their banking passwords (as was needed for screen-scraping).
According to recent reports, participation in the CDR ecosystem has grown steadily, with millions of data calls now being made daily. This isn’t just a regulatory project anymore; it is becoming the standard for digital financial interaction in Australia.
Why have businesses hesitated?
If the future is so bright, why are some lenders and advisers still clinging to screen scraping? The hesitation usually comes down to four perceived hurdles.
1. “Screen scraping is more complete”
Historically, this was true. Screen scraping could grab almost anything visible on an internet banking interface. Early CDR data standards had gaps, particularly around complex business accounts or specific transaction details. However, the gap has narrowed dramatically. The quality of CDR data feeds – structured, standardised, and API-driven – is now far superior to the unstructured “mess” that screen scraping often returns.
2. “It’s not real-time”
There is a lingering myth that CDR data is slower. While some banks initially struggled with API latency, performance standards enforced by the ACCC have tightened. Conversely, screen scraping is increasingly fragile; every time a bank updates their website interface or introduces multi-factor authentication (MFA), screen scrapers break. That downtime is a far bigger risk to “real-time” decision-making than API latency.
3. “The compliance is too hard”
This is the big one. The CDR is indeed a complex world of accreditation levels, information security controls, and consent dashboards. For a lender or software provider focused on building great products, navigating the CDR rules can feel like a distraction.
However, the compliance burden doesn’t have to be a blocker. By teaming up with the right legal and technical advisors, you can leverage their expertise to navigate the complexities of the CDR, most critically, selecting the right ‘model’ of CDR data sharing.
4. “The customer experience is poor for businesses”
A further challenge has been ensuring the digital consent process works easily for business banking users. While CDR/Open Banking enables a streamlined digital consent journey – vastly improving on paper-based processes – many business operators are not nominated representatives for their accounts, even if they have authority to operate them.
To solve this, a number of solutions are being explored. One approach is encouraging banks to adopt more inclusive, “in by default” models for authorising representatives. This would mean that individuals with the authority to operate an account are automatically able to provide consent for data sharing, removing a significant hurdle for businesses. Additionally, the government is considering changes to the CDR rules to better accommodate complex business structures and make it easier for the right people within a company to grant consent.
In the meantime, free services such as cdrready.com.au enable consumers to easily check which accounts they are a nominated representative for, and provides instructions of how to fix this where they aren’t.
Despite the perceived hurdles, the business case for moving to CDR in 2026 is undeniable.
Security and trust
Screen scraping requires your customers to share their banking passwords. In an era of high-profile data breaches (think Optus and Medibank), asking customers to violate their own bank’s terms and conditions by sharing passwords is a massive friction point. With CDR, neither you or any third party ever sees the credentials; you just get the data. This builds trust and significantly lowers your security risk profile.
The banks are closing the door on screen scraping
Perhaps the most pressing reason to act now is the accelerating demise of screen scraping. Screen scraping has long been criticised for its poor security and unreliable performance, with customers required to disclose sensitive banking credentials and facing regular disruptions whenever banks update their login processes.
Banks across Australia have always opposed screen scraping, but now that CDR offers a more secure, regulated alternative, they are moving decisively to block such access. Several major banks, including Commonwealth Bank, are leading this shift by actively preventing screen scraping and advancing bank-approved methods for customer data delivery. There is also growing momentum for an outright ban on screen scraping within the industry – making it increasingly risky for businesses and software platforms to depend on it. If your product still relies on scraping, it’s operating on borrowed time. Transitioning to CDR now ensures you’re not caught out by these inevitable changes and positions you to deliver secure, reliable services as the new standard takes hold.
Global momentum
Looking overseas, we can see the trajectory. In the UK, Open Banking has exploded, with over 7 million active users. In Europe, it’s even larger. The lesson from the overseas is that once the tipping point is reached, adoption accelerates rapidly. Australia is approaching that tipping point now.
How SISS Data Services bridges the gap
We understand why you haven’t moved yet. The complexity is real, and the technical lift seems daunting.
This is where SISS Data Services comes in. Some call us ‘the quiet achievers’ in Australian bank data. For 15 years we have single-mindedly focus on delivering highly secure, highly accurate, highly reliable bank data feeds. We aren’t just another API provider; we are the most experienced bank data team in the country.
We solve the “hurdles” mentioned above:
- Compliance simplified: We help you select the right model, drastically reducing your compliance burden and liability so you can focus on your product.
- Hybrid strength: We know CDR isn’t ideal for all use cases. That’s why we also offer direct bank data feeds through our direct contracts with all of Australia’s major banks. This allows us to provide a “complete picture” solution, without resorting to workarounds like screen-scraping. Everything we do is bank approved.
- Customer-centric build: We don’t just dump documentation on you. Our experienced, local, team will work closely with you to build workflows that put customer experience at the centre, ensuring high conversion rates during the consent process, and high reliability day-in, day-out. And when there’s a question, we provide Customer Support, including a 24/7 option.
Ready to future-proof your product?
2026 is the year the training wheels come off. The banks are moving on, the regulators are moving on, and your customers are expecting better security.
Don’t let legacy technology hold your product back.
Enquire here to find out how SISS can support your transition to CDR today.
by Grant Augustin, Founder & CEO


