Consumer Data Right

Experian Open Data Solutions (NZ) Limited (“Experian” or we/us) is accredited as an Accredited Requestor (Intermediary) under New Zealand’s Consumer Data Right (“CDR”) framework, which is established by the Customer and Product Data Act 2025 (“CPD Act”) and related regulations. This explains how we collect, hold, use, and disclose CDR Data, and describes your rights in relation to that data.

For details about the registered participants in the CDR framework please refer to the Ministry of Business Innovation & Employment website.

Please note this document should be read in conjunction with Experian’s Privacy Policy

What is CDR Data?

CDR Data means specific customer data obtained by Experian from a data holder (such as a bank) under the CDR framework, following your authorisation. This may include banking and transaction data about you that is held by your bank, as designated under the Customer and Product Data (Designations for Banking and Other Deposit Taking) Regulations 2025.

CDR Data is distinct from other personal information that Experian’s related companies may hold about you and is subject to additional obligations described in this section.

How do we collect CDR Data?

We collect CDR data electronically through secure application programming interfaces (APIs) as the approved CDR data-sharing method. When you provide your consent, we request the relevant CDR data from the accredited data holder, which securely transmits the requested information to us through the CDR ecosystem.

We only collect the CDR data for which you have given a valid authorisation. An authorisation is your express consent, given through the secure consent interface, directing a data holder to share specified data with us for a specific purpose.

We will not collect CDR Data without your authorisation.

We act as an intermediary, collecting CDR Data on behalf of businesses that use our platform (“Service Recipients”). We supply the CDR Data available to the relevant Service Recipient in accordance with your authorisation.

Why do we collect CDR Data and how do we use it?

We will only use CDR Data for the specific purpose you authorised at the time your authorisation was given. We will not use CDR Data for any purpose that is inconsistent with that authorisation, this means:

  • we will not use CDR Data for direct marketing purposes;
  • we will not combine CDR Data with other data we hold about you for purposes beyond those you have authorised; and
  • we will not on-sell CDR Data to third parties.

We collect and use your CDR data to assist you with sharing transaction and financial information with your nominated Service Recipient. The specific purposes for which CDR Data may be collected and used will be described to you in the authorisation process before you provide your consent.

How do we hold CDR Data?

We do not ordinarily retain CDR data, if we temporarily hold your data it is held in its digital form, and stored in a cloud-based service environment controlled by us. For more information on how we hold data please also refer to “How secure is your personal information?” section of our Privacy Policy.

We take reasonable steps to ensure that CDR Data is held only for as long as necessary for the purpose for which it was collected as authorised. When your authorisation ends, or when CDR Data is no longer required for the authorised purpose, we will delete that data.

CDR Data may be stored or processed outside of New Zealand, including in Australia.

Where CDR Data is held or processed offshore, we ensure that equivalent privacy and security protections apply to that data as required by New Zealand Privacy Laws and the CPD Act.

Who do we disclose CDR Data to?

We will only disclose CDR Data to the party you authorise. This may involve disclosing CDR Data to:

  • Service Recipients – businesses that use our platform as an intermediary service, where your authorisation expressly covers that disclosure.
  • our contractors and technology service providers, solely for the purpose of enabling us to provide these services; and
  • government agencies or enforcement bodies, where required by law.

We will not disclose CDR Data to any third party except to those authorised by you or necessary to provide the service to you.

Managing your authorisation

You are in control of your authorisation at all times. You may withdraw your authorisation at any time by contacting us at cdrnz@experian.com. or through the authorisation management interface provided as part of the relevant service. Withdrawal of your authorisation will take effect promptly, and we will cease collecting CDR Data from the relevant data holder upon withdrawal.

Withdrawing your authorisation may affect the availability of the service for which the CDR Data was being used. Please check with your service provider for more specific details on how this may impact the service they provide to you.

In accordance with the Customer and Product Data (General Requirements) Regulations 2025, we will send you a written notice at least once every 12 months reminding you of the scope of any active authorisation you have given us and explaining how you can end it.

Your rights in relation to CDR Data

In addition to your rights under the Privacy Act 2020, you have the following rights in relation to CDR Data:

  • the right to give, manage, and withdraw your authorisation for us to collect and use CDR Data at any time;
  • the right to request access to any CDR Data we may hold about you (as noted previously we will generally not retain CDR information beyond the period required to provide our services to the authorised party); and

To exercise any of these rights, please contact us at cdrnz@experian.com.

CDR complaints

If you have a complaint about the way we have handled your CDR Data, you may raise it with us by contacting us at cdrnz@experian.com.

If your complaint is not resolved to your satisfaction, you may refer the matter to:

  • the Privacy Commissioner Te Mana Matapono Matatapu, for complaints involving personal information (refer to www.privacy.org.nz for more details); or
  • the Ministry of Business, Innovation and Employment (“MBIE”), as the CDR Regulator, for complaints relating to our obligations under the CPD Act (refer to www.mbie.govt.nz for more details).

 

"Privacy Laws" (amended definition for this CDR Policy) means the Privacy Act 2020 (including the Information Privacy Principles), the Credit Reporting Privacy Code 2020 (in relation to credit reporting information), and the Customer and Product Data Act 2025 and its related regulations (in relation to CDR Data).

"Service Recipient" means a business to whom Experian provides an intermediary service under the CDR framework, as described in this Consumer Data Right Policy.