Open Banking
Open Banking is a government-regulated system that allows consumers and businesses to securely share their banking data with accredited third-party providers, such as: fintech companies, budgeting apps, lenders and other financial institutions. It operates under Australia's Consumer Data Right (CDR) framework.
As of mid-July 2026, the Australian government announced that CDR will be expanding to include large non-bank lenders and Buy Now, Pay Later (BNPL) providers. Non-bank data must meet the same high security and privacy standards as banks, ensuring that financial information is protected no matter where it is held. Consumer data sharing for non-bank lenders will be phased in from November 2026, depending on the size of the provider.
Consumer Data Right (CDR)
The Consumer Data Right (CDR) was introduced by the Australian Government to give consumers more choice and control over how their data is shared.
Under the Competition and Consumer Act 2010 and the Competition and Consumer (Consumer Data Right) Rules 2020 (CDR Laws), consumers can ask for their data to be securely transferred to an accredited provider so they can investigate, compare and access services more easily. In the banking sector, this is referred to as “Open Banking”.
To learn more about CDR, and your rights regarding the use of your personal data, please refer to our Consumer Data Right (CDR) Policy.
Open Banking
Open Banking is an evolving, economy-wide reform that is being embedded in the banking sector across Australia. It was originally introduced in 2020 and, with effect from late-2026, will also include the non-bank lending sector.
Non-bank lenders are financial institutions that provide credit or loans but do not hold a full banking licence and are not an Authorised Deposit-taking Institution (ADI), which means they do not take customer deposits in the way that banks do. They can include mortgage lenders, car finance providers, personal loan providers and Buy Now, Pay Later (BNPL) providers.
Banks can now provide a more complete view of your finances by securely integrating your non-bank loan and BNPL data. This visibility supports more responsible lending decisions and allows your bank to offer tailored solutions based on your full financial situation.
Consumer Data Right (CDR) is the Australian Government framework that provides consumers and businesses with greater control over their data. It is essentially the enabling law that underpins Open Banking.
Instead of manually downloading and sending your data, the CDR enables your data to be transferred securely and electronically between organisations that participate in the scheme. The sharing only occurs with your explicit consent and under strict privacy and security rules.
Whilst CDR is prominent within the Banking sector, it is also active in the following:
- Energy; including electricity usage and account information; and
- Non-bank lenders and Buy Now, Pay Later (BNPL) providers.
Yes. A joint account holder/signatory can share your data through Open Banking if they are set up as a delegate within Open Banking. This must be done by the account owner or controlling person.
At a high-level, the opt-in process follows these steps:
1. Determine the participating provider, e.g. the financial institution you use for your everyday banking
- Initiate an activity with the requesting institution (for example, a prospective home loan provider) through one of your providers services; mobile app, internet banking portal, budgeting tool, comparison service, etc.
- The provider must be accredited to send/receive CDR data.
2. Provide your explicit consent
- The provider will clearly illustrate:
- What data will be accessed;
- Why it is needed;
- How long access will last; and
- Which account(s) will be included.
- You retain complete control over the selection of each individual data item and must actively consent to proceed before any data can be shared.
3. Authenticate with your bank
- You will be redirected to your bank's secure authentication page and sign-in using your normal banking credentials.
- The party that you are interacting with will never receive your online banking identity or password.
4. Review and approve
- Your bank will present a consent screen containing the following:
- The accredited recipient;
- The account(s) to be shared;
- The types of data requested; and
- The duration of the consent.
- You can then confirm your final approval to proceed.
5. Data sharing begins
- Once approved, the bank securely shares the authorised data with the accredited provider via CDR APIs.
- API stands for Application Programming Interface. It is a set of rules and protocols which allow software applications to communicate and share data with one another.
- To reiterate, Open Banking in Australia is strictly opt-in. Customers must provide explicit consent before any banking data is shared, and they remain in control of that consent throughout the sharing period.
Your data will only be made available through Open Banking if you opt-in to provide information to an accredited third-party, so the decision on whether your data is made available or not is entirely yours.
You can also change your mind and revoke your consent at any time.
You can revoke your Open Banking (Consumer Data Right) consent at an individual Member-level at any time. The simplest way to complete this is via our digital channels. Please refer to the following for guidance:
Mobile App
- Log into the app and tap the menu icon in the top-left corner of the home screen.
- Select ‘Settings’.
- Select ‘Sharing Management’.
- Follow the on-screen prompts to complete the stop sharing
Internet Banking
- Log into Internet Banking and select ‘Services’ from the header menu at the top of the home screen.
- Select ‘Sharing’.
- Request an SMS Code to validate your mobile phone number.
- Follow the on-screen prompts to complete the stop sharing
Alternatively, you can visit your local branch or call our Contact Centre on 1800 075 078 and our friendly staff will be able to support you with the process of opting-out.
Please note:
Changes to your consent for existing agreements (i.e. where you’ve previously authorised data sharing for specific accounts or products) can be made at any time through the Accredited Data Recipient (ADR). The ADR is the party that you agreed to share your data with. For example, you may wish to change:
- The number or type of accounts which you initially consented to share; or
- The duration of how long the data from those accounts can be shared.
You cannot make changes to your individual consent agreements through Queensland Country Bank. However, you retain the right to cancel these at any time via the relevant parties.
The security of your banking data is of the highest importance to Queensland Country. Our privacy safeguards will ensure that you are in control of which companies access your data and how they use it. Open Banking will only allow access to your data if you give permission for an accredited data recipient to receive it.
Third parties providing services via Open Banking must be accredited by the Australian Consumer and Competition Commission (ACCC) and comply with all privacy and security requirements. The ACCC is the lead regulator of the Consumer Data Right (CDR) and works very closely with the Office of the Australian Information Commissioner (OAIC) and the Data Standards Body (DSB) to manage all aspects of development, implementation and governance.
For further details, you can view our Consumer Data Rights (CDR) policy.
For Developers
Queensland Country Bank’s Open Banking Product Reference Data (PRD) API enables third parties to retrieve information about our current products in a machine readable format.
For detailed information about our available API's, please visit our Open Banking developers page.
Still have questions?
If you still have questions, you can easily reach out to us.