CBA pays record $792,000 fine for consumer data right breach


The Commonwealth Bank has paid a record $792,000 fine under Australia’s Consumer Data Right (CDR) scheme for failing to enable data sharing on a small number of business accounts.

The big four bank paid the penalties after voluntarily reporting the issue and being furnished with four infringement notices by the Australian Competition and Consumer Commission.

The ACCC alleges that CBA “did not comply” with CDR rules when it failed to enable data sharing on accounts with a Trading Entity Business Name (TEBN) customer profile.

Image: Shutterstock.com/JHVEPhoto

The infringement notices relate to four consumers who were unable to share their data to access CDR-enabled products and services, including those used for accounting.

The ACCC said customers with a TEBN — a profile type typically used by business that operate under a different name from their legal one — were required to “perform manual workarounds or revert to less secure methods of data sharing”.

As part of the administrative resolution, CBA has committed to enabling consumer data sharing for remaining TEBN accounts by 19 December and offered goodwill payments to impacted customers.

Business customers that are able to “substantiate further financial and non-financial loss” will also be able to apply for additional payments, the ACCC said in a statement on Tuesday.

ACCC deputy chair Catriona Lowe said the CBA penalty was the “highest total penalty to date for an alleged breach of the CDR rules”, following a $751,200 paid by National Australia Bank in June.

NAB’s violation related to its failure to disclose credit limit information to four separate requests made by fintechs offering services, such as mortgage brokering tools, accredited under the scheme.

Other recent fines include a $33,000 penalty against global banking giant HSBC in 2024, as well as a $133,200 penalty against the Bank of Queensland and $55,280 against ING, both in 2022.

“We will continue to focus our compliance and enforcement efforts to enable the benefits the CDR system delivers for consumers including more choice and greater access to better deals on products and services,” Ms Lowe added.

CBA has been an accredited CDR data holder since July 2020 and a data recipient since March 2021. It later enabled data sharing for business accounts in November 2021.

In a statement, the bank said that an investigation of the matter found that data sharing had not been enabled on some business account types when data sharing was enabled.

“CBA accepts the findings of the ACCC’s investigation into CBA’s compliance with its CDR obligations, and we apologise to our customers affected by this issue,” it said on Tuesday.

Ms Lowe said the penalty against CBA “should serve as a reminder to all CDR participants that failing to comply with the Rules may result in the ACCC taking enforcement action”.

Do you know more? Contact James Riley via Email.

Leave a Comment

Related stories