• Contact
  • Feedback
Banking Day
ConfidentiallySpeaking.com.au Logo
High-impact negotiation masterclass | July 9 & 16, 2025 | 5:00pm - 8:30pm
This high-impact negotiation masterclass teaches practical strategies to help you succeed in challenging negotiations.
Register Now
  • News
  • Topics
    • All Topics
    • Briefs
    • Major Banks
    • Authorised deposit-taking institutions
    • Insurance, funds and super
    • Payments, mobile & wallets
    • Consumer lending
    • Mortgages
    • Business lending
    • Finance regulation
    • Debt capital markets
    • Ratings agencies
    • Equity capital markets
    • Professional services
    • Work & career
    • Foreign news
    • Other topics
  • Free Trial
  • Subscribe
  • Resources
    • Industry events
  • About us
    • About Banking Day
    • Advertise
    • Feedback
    • Contact Banking Day
  • Search
  • Login
  • My account
    • Account settings
    • User Admin
    • Logout

Login or request a free trial

Big bank CDR privacy safeguards could be better

24 November 2021 6:43AM

The big banks have some work to do to get their Consumer Data Right privacy safeguards up to best practice, according to a review of their performance.

The Office of the Australian Information Commissioner has released an assessment of how the big banks are complying with CDR privacy safeguard 1, which requires CDR entities to have a policy describing how they manage CDR data, and to maintain internal practices, procedures and systems to ensure compliance.

The OAIC, which regulates the privacy aspects of CDR, said it did not identify any areas of “high privacy risk” which would likely lead to a breach of legislative obligations.

However, it identified at least one medium privacy risk for each bank – and four risks in one case. These are defined as risks that could possibly lead to a breach of legislative obligations.

The majority of these risks related to the way the banks had implemented internal practices, procedures and systems to ensure compliance with their CDR obligations.

The OAIC said all four banks had developed a CDR policy distinct from their other privacy policies, and each bank’s CDR policy was available and accessible free of charge. 

It said the banks were taking steps to promote “a culture that respects privacy and good information handling practices” and had senior staff providing leadership of their CDR programs.

Among the areas for improvement, the OAIC said three banks did not provide sufficient detail about their complaints processes.

It recommended that three banks advise customers that they can access all their CDR data and have any errors corrected.

The internal practices, procedures and systems of one bank did not include sufficient detail about CDR related requests customers can make of data holders. 

One bank did not demonstrate that it provided CDR training to all relevant staff members before they handled CDR data.

I'm a returning subscriber

*
Password reset *
Login

Request a free trial

  • Emailing you the news at 7am.
  • Covering core lending and funding issues, strategy, payments, regulation, risk management, IT, marketing and more.
  • Original news and summaries of major stories from other media – ditch your newspaper subscriptions.
  • Focused on banking and finance, saving you the time spent wading through newspapers and other services.
  • With reporting from former editors and senior writers from the AFR and The Australian.
  • Configured for your phone, laptop and PC.
Free trial Banking Day
ConfidentiallySpeaking.com.au Logo
High-impact negotiation masterclass | July 9 & 16, 2025 | 5:00pm - 8:30pm
This high-impact negotiation masterclass teaches practical strategies to help you succeed in challenging negotiations.
Register Now

Consumer lending

  • Latitude, Harvey Norman liable for interest free GO card con

Copyright © WorkDay Media 2003-2025.

Banking Day is a WorkDay Media publication

WorkDay Media Unit Trust

  • Privacy policy
  • Terms of access and use