About the schedule
The ACCC monitors and enforces compliance with the CDR obligations set out in the Competition and Consumer Act 2010 (Cth), the Competition and Consumer (Consumer Data Right) Rules 2020 (the CDR Rules) and the Consumer Data Standards.
Data holders’ obligations commenced on various dates - see the CDR rollout.
Some data holders have received an exemption from certain obligations under s56GD of the Act. The CDR exemptions register lists all exemptions granted.
This rectification schedule sets out information provided by data holders to the ACCC. We have published this information to provide a reference for accredited data recipients and consumers regarding potential issues in data holders’ CDR implementations.
We expect data holders to promptly rectify their non-compliance or face possible enforcement consideration in line with the ACCC/OAIC Compliance and Enforcement Policy for the Consumer Data Right. Listing an issue on this rectification schedule does not preclude the ACCC from pursuing compliance or enforcement action in-line with this policy.
Data holders that are not currently active on the CDR Register and do not have an exemption from this requirement are listed in a separate rectification schedule.
This table is current as at 5 October 2026.
Banking - major data holders
The data holders listed in the table below are the four major data holders and their non-primary brands.
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
| CommBank |
|
15 December 2026 |
| 2. The consumer data request service, for certain accounts that are held under Trusts with one or more individual trustee(s) and accessed via NetBank to be uplifted so that a nominated representative is not required. | 28 February 2027 | |
| CommBiz | 3. CBA to: (a) enable data sharing for accounts held by customers under a ‘Trust, Deceased Estates’ in CommBiz and (b) uplift the CommBiz consumer data request service for accounts held under Trusts with one or more individual trustee(s) so that a nominated representative is not required. | TBC |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
National Australia Bank Limited (NAB) Brands: National Australia Bank |
1. Guarantors of trust accounts may experience issues in establishing data sharing for those accounts due to limitations on guarantor accounts. Specific work arounds are available. A strategic solution to address this is being implemented. | 30 September 2026 |
|
National Australia Bank Limited Brands: UBank |
|
30 October 2026 |
Banking - non-major data holders
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
AMP Bank Ltd Brand: AMP Bank GO |
1.Customers using the AMP Bank GO banking brand to share data will be authenticated via its digital app using App2App and Web2App technology, rather than by One Time Password (OTP). App2App and Web2App technology forms part of the Data Standards Body DP 327 - Authentication Uplift Phase 1 that includes a recommendation that online customers can authenticate with their Data Holder's app. | TBC |
|
B & E Ltd Brand: Bank of us |
1. Applicability Conditions on Account Details | TBC |
| 2. Term Deposit rate and tier availability | TBC | |
|
Bank Australia Limited Brand: Bank Australia |
|
30 December 2026 |
|
Bank of Queensland Limited Brands: Bank of Queensland Limited Virgin Money BOQ Specialist DDH Graham |
1. Customers on legacy platforms do not experience commensurate latency | TBC |
|
Bank of Queensland Limited Brands: Bank of Queensland Limited |
2. A subset of Sole Traders under our Bank of Queensland brand are incorrectly classified as ineligible for CDR. | TBC |
|
Beyond Bank Australia Limited Brand: Beyond Bank Australia |
1. High Performance APIs not within threshold limit | TBC |
|
BNK Banking Corporation Limited Brand: BNK Bank (Goldfields Money/BCHL) |
1. CDR arrangement for Secondary Users cannot be accommodated by definition because Secondary Users do not exist within the Core Banking Systems of BNK | 31 December 2028 |
| 2. Phase 1 - The 24-hour delay in certain CDR data availability due to old version (R16) of existing Core Banking System (T24) | 31 December 2028 | |
| 3. Not able to occasionally meet the 1500ms response time for some of the Low Priority APIs due to information required being obtained via multiple core APIs from our old version (R16) of our existing Core Banking System (T24) | 31 December 2028 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Cairns Penny Savings & Loans Limited Brand: Cairns Bank |
|
31 October 2026 |
|
Central Murray Credit Union Limited Brand: Central Murray Bank |
1. Incorrect format for Product fee accrualFrequency | TBC |
| 2. CDR 1.35 release | 15 October 2026 | |
| 3. Term Deposit rate and tier availability | 15 October 2026 | |
| 4. Applicability Conditions on Account Details | 15 October 2026 | |
|
Coastline Credit Union Limited Brand: Coastline Bank |
|
10 November 2026 |
|
Defence Bank Limited Brand: Defence Bank |
|
30 October 2026 |
|
Dnister Ukrainian Credit Co-operative Limited Brand: Dnister |
|
10 November 2026 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Ford Co-operative Credit Society Limited Brand: Geelong Bank |
1. Invalid format for accrualFrequency on all product fees | TBC |
|
Brand: Gateway Bank |
|
30 October 2026 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Heartland Bank Australia Limited Brand: Heartland |
1. Get Account Detail v4 not yet supported. | 31 December 2026 |
|
Heritage and People's Choice Ltd Brand: Heritage Bank |
1. Get metrics data reflects measurements at data holder level. | 30 November 2027 |
|
ING Bank (Australia) Limited Brand: ING Bank (Australia) Limited |
1. Fixed term expiry date not populated in additionalInformation for lendingRates Fixed term expiry date, inside additionalInformation for lendingRates, is not currently populated. This affects the Account Details API, specifically the BankingProductLendingRateV3 object, where lendingRateType is FIXED. |
31 October 2026 |
|
2. financialInstitution not populated for direct debits financialInstitution is not currently being populated for affected direct debits. This affects the Bulk Direct Debits and Direct Debits For Specific Accounts APIs, specifically the BankingAuthorisedEntity object. |
31 October 2026 | |
|
3. loanEndDate not returned for mortgage accounts loanEndDate is not currently being returned for affected mortgage accounts. This affects the Accounts and Account Details APIs, specifically the BankingLoanAccountV3 object. |
31 October 2026 | |
|
4. Incorrect nextInstalmentDate for loan accounts nextInstalmentDate is currently being calculated incorrectly for affected loan accounts. This affects the Accounts and Account Details APIs, specifically the BankingLoanAccountV3 object. |
31 October 2026 | |
|
Judo Bank Private Limited Brand: Judo Bank |
1. Get Payees, Get Payee Detail, Get Scheduled Payments and associated endpoints are currently returning 500 errors. | 31 December 2026 |
|
Liberty Financial Pty Ltd Brand: Liberty Financial |
1. Secondary user functionality (Rules 1.13(1)(e) and 1.15(5)) Products not designed for secondary user functionality. Manual functionality available in limited circumstances (where necessary). | TBC |
|
MyState Bank Limited Brand: Auswide Bank Ltd |
1. Unable to deliver v1.35.0 and v1.36.0 upgrade by compliance date 13 July 2026 as required by Consumer Data Standards | 30 October 2026 |
|
Newcastle Greater Mutual Group Limited Brand: Greater Bank |
1. When applying Rule 1.10B & Part 2 of Schedule 3, CDR Consumer Eligibility is determined at the Brand level (Newcastle Permanent and Greater Bank) not the Legal Entity level (NGM Group). | TBC |
|
Newcastle Greater Mutual Group Limited Brand: |
2. CDR v5 dashboard changes to display the details of each authorisation’s amendment linked by cdr_arrangement_id | TBC |
|
Northern Inland Credit Union Limited Brand: |
|
30 November 2026 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Police Bank Ltd Brand: Border Bank Police Bank |
1. Certain product-related data elements expected to be returned within Consumer Data Account Detail API responses are currently incomplete for some products. The issue affects account-level information including certain product attributes such as lending rates, deposit rates, fees and other associated product information that support Consumer Data API responses. |
30 September 2026 |
| 2. The isActivated field is unexpectedly present within the features array returned by the Get Product Detail endpoint, resulting in a standards conformance anomaly. | 31 January 2027 | |
|
Police Financial Services Limited Brand: BankVic |
1. Open Banking Update - CDR Standards v1.35.0, v1.36.0 | 15 September 2026 |
|
Police & Nurses Limited Brands: P&N Bank BCU |
1. High Performance API’s not within threshold limit | TBC |
|
QPCU Limited Brands: QBANK |
1. Unable to deliver CDR Standards v1.35.0 and v1.36.0 and by compliance date of 13 July 2026 as required by Consumer Data Standards | 9 November 2026 |
| 2. applicabilityConditions not appearing in the BankingAccountDetailV4 response | TBC |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
| No entries currently displayed |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Teachers Mutual Bank Limited Brands: Firefighters Mutual Bank Health Professionals Bank Teachers Mutual Bank UniBank |
|
TBC |
|
Teachers Mutual Bank Limited Brands: Firefighters Mutual Bank Health Professionals Bank Teachers Mutual Bank UniBank |
2. A subset of non-individual Members are unable to establish CDR data sharing consents. | TBC |
|
Transport Mutual Credit Union Limited Brand: TMCU |
1.v1.33.0; retire existing hybrid protocol and supporting Authorisation Code Flow (ACF) | TBC |
|
Brand: bankWAW |
|
20 November 2026 |
|
Woolworths Team Bank Limited Brand: Woolworths Team Bank |
2.CDR v1.33.0 - Unable to meet Mandate deadline 12 May 2025 due to constraints from External Software provider. | 30 November 2026 |
| 3. no CDR arrangement ID available | 30 November 2026 | |
| 4. Residential Mortgage PRDs with a Feature Type issue | 30 November 2026 | |
| 5. ANZ Plus DCR with Woolworths Team Bank - ADR JWKS could not be retrieved. | 30 November 2026 |
Energy - data holders
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Aurora Energy Pty Ltd Brand Aurora Energy |
|
1 November 2026 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Sumo Power Pty Ltd Brand Sumo Power (legacy) |
|
31 December 2026 |
| Data holder (brand) | Issue | Proposed resolution date |
|---|---|---|
|
Powershop Australia Pty Ltd Brands: Kogan Energy Powershop |
|
TBC |
Non-bank lending - data holders
|
Toyota Finance Australia Ltd Brands: Hino Financial Services Lexus Financial Services Mazda Finance PowerTorque Finance Power Alliance Finance Suzuki Financial Services Toyota Finance |
|
31 December 2027 |
|
Toyota Finance Australia Ltd Brands: Hino Financial Services Lexus Financial Services Mazda Finance PowerTorque Finance Power Alliance Finance Suzuki Financial Services Toyota Finance |
2. For Account Information, Customer Information and Transaction Information shared as CDR Data, customers may experience up to 24 hours data latency from the customer portal view. | 31 December 2027 |