At a high-level, the opt-in process follows these steps:
1. Determine the participating provider, e.g. the financial institution you use for your everyday banking
- Initiate an activity with the requesting institution (for example, a prospective home loan provider) through one of your providers services; mobile app, internet banking portal, budgeting tool, comparison service, etc.
- The provider must be accredited to send/receive CDR data.
2. Provide your explicit consent
- The provider will clearly illustrate:
- What data will be accessed;
- Why it is needed;
- How long access will last; and
- Which account(s) will be included.
- You retain complete control over the selection of each individual data item and must actively consent to proceed before any data can be shared.
3. Authenticate with your bank
- You will be redirected to your bank's secure authentication page and sign-in using your normal banking credentials.
- The party that you are interacting with will never receive your online banking identity or password.
4. Review and approve
- Your bank will present a consent screen containing the following:
- The accredited recipient;
- The account(s) to be shared;
- The types of data requested; and
- The duration of the consent.
- You can then confirm your final approval to proceed.
5. Data sharing begins
- Once approved, the bank securely shares the authorised data with the accredited provider via CDR APIs.
- API stands for Application Programming Interface. It is a set of rules and protocols which allow software applications to communicate and share data with one another.
- To reiterate, Open Banking in Australia is strictly opt-in. Customers must provide explicit consent before any banking data is shared, and they remain in control of that consent throughout the sharing period.
Related FAQs
FAQ by topic
Looking for something specific? Find it by topic.