The Consumer Data Right just got bigger. Your build shouldn't have to.
At least 35 non-bank lenders entered the Consumer Data Right in July 2026. What the expansion means for product roadmaps, and the three ways teams get access.
By Max Diamond, openfeed — powered by Biza.io

On 13 July 2026, non-bank lenders joined the Consumer Data Right. At least 35 new data holders entered the regime, starting with product information (i.e. rates, fees, eligibility criteria, etc.) and consumer data sharing phases in from 9 November 2026 based on provider size.
More than 1.3 million Australians now use the CDR. That’s up 135% in a year.
If you own a product roadmap, that’s two pieces of news at once. The data set you can build on just widened. And the integration job you’ve been deferring got one sector bigger.
The plumbing is not the interesting part, but it is the expensive part.
The CDR works. The problem has never been the regime’s ambition; it’s the cost of standing in it.
When the Government reviewed CDR compliance costs, the major banks’ implementation programs ran past $100 million each, and smaller institutions past $1 million. Those are data holder numbers, not yours. But the recipient side has its own version of the same bill: accreditation measured in months, six-figure budgets, legal review, and per-holder connections that need maintaining long after launch.
That maths is why the sanctioned path stayed empty for so long, and why so many teams kept screen-scraping instead. The Government has since called screen scraping “fundamentally unsafe” and asked Treasury to advise on a full and formal ban. Whatever lands, the direction is not ambiguous.
Three doors to shipping your product. Which one do you use?
Become accredited yourself. Full control, direct access, and a compliance function you now employ permanently. For a scale-up, that’s a headcount decision disguised as an integration decision.
Keep scraping. Fast to ship, and it works until a bank changes a login page or blocks you outright. Your users hand over their banking passwords to get there. Your risk committee already knows this.
Let the feed carry it. Consented data through one API, with consent, revocation and compliance handled by the platform. Your team builds the feature; someone else owns the regulatory change.
The question that actually decides it
Not “can we get the data?”. You can, three ways. The question is who wears the next rule change.
If your team is accredited, you do. If you’re scraping, you wear the breakage and the reputational risk. If the feed carries it, the change lands on the platform’s roadmap instead of yours.
That’s the design principle behind openfeed. It’s built by Biza, the team behind 30+ live data holder implementations, running under ISO 27001, SOC 2 Type 2, FAPI 2.0 and ASAE 3150 assurance.

Three questions for your next sprint planning
- What is the CDR line in your roadmap actually costing you?
- When a user hits your consent flow, what share of them survive it?
- If data access were one sprint instead of one quarter, what would you ship next?

