Standards for the Consumer Data Right
Standards provide the practical requirements needed to support secure, consistent, and interoperable participation in the Consumer Data Right (CDR). Explore CDR standards, how they are developed, and how participants and other interested parties can contribute to future standards development.
On this page I tēnei whārangi
About Consumer Data Right standards
Standards set out the technical and operational requirements that participants need to implement and follow in practice. They will evolve over time to support new sectors, innovation, customer outcomes, and effective operation of the Consumer Data Right framework.
What standards are
Standards are practical requirements, instructions, and specifications made within the CDR regulatory framework. They explain how participants must implement, or may choose to adopt where optional content is clearly identified, obligations and settings established by the Act, regulations, or other lawful CDR requirements.
Standards are not a replacement for the law. They sit beneath the Act and regulations and provide the operational, technical, procedural, or information detail needed for the CDR to operate consistently, securely, and reliably.
CDR standards may be technical, non-technical, or a combination of both.
Technical standards
Technical standards set the technical requirements needed for secure, reliable, and interoperable participation in the CDR. They support how participants identify and trust each other, how systems exchange data or carry out designated actions, and how technical requirements can be implemented, tested, and monitored consistently.
Non-technical standards
Non-technical standards explain how participants are expected to meet CDR requirements in practice where those requirements are not mainly about system-to-system exchange. They provide operational detail that supports consistent implementation of obligations already established elsewhere in the framework. They do not replace the law, create obligations outside the law, or prescribe internal business choices unless that prescription is needed for compliance, interoperability, security, reliability, customer protection, or effective oversight.
How standards are developed
As CDR Regulator, MBIE works with participants and other contributors to inform the development, maintenance, and future direction of CDR standards. This helps ensure standards are practical, responsive, and informed by implementation experience.
CDR standards are managed through a structured process that supports transparency, consistency, and effective implementation. Participants and other interested parties can raise issues, suggest improvements, provide evidence, and contribute feedback on proposed changes. MBIE considers this input alongside customer outcomes, implementation impacts, regulatory requirements, and the long-term operation of the CDR when making standards decisions.
Standards changes are assessed, prioritised, developed, approved, published, and monitored through a defined lifecycle to ensure they remain effective and fit for purpose, and so participants have clear visibility of what applies and what is changing.
Standards roadmap and future development
MBIE uses standards roadmaps to provide visibility of likely future standards work and sector development priorities. Roadmaps help participants understand potential areas of focus, emerging opportunities, and longer-term developments before detailed standards changes are proposed.
Roadmaps are informed by participant input, implementation experience, market developments, and sector needs. They help support forward planning, identify opportunities for innovation and improvement, and guide the future evolution of CDR standards across designated sectors.
MBIE manages standards changes through planned release cycles that range from minor corrections and clarifications to larger enhancements and new functionality. Version management, publication, and participant communications help ensure there is clear visibility of what applies, what is changing, and when changes take effect.
Standards governance and stakeholder engagement
Standards are developed and maintained by MBIE as the CDR Regulator, and shaped via input from participants and other contributors. MBIE works with industry to understand implementation impacts, sector needs, technical considerations, and opportunities for improvement, helping ensure standards remain practical, effective, and fit for purpose over time.
Regulated open banking standards
Regulated open banking standards establish clear rules for how banks and accredited requestors share customer data and payment initiation requests securely and efficiently. They enable customers to authorise their bank to share data with trusted service providers, such as fintechs, and to initiate payments on their behalf.
About the regulated open banking standard
The Customer and Product Data (Banking and Other Deposit Taking) Standards 2025 set out the technical, security, and operational requirements for regulated open banking in New Zealand. These standards are issued under the Customer and Product Data Act 2025 and came into force on 1 December 2025.
The standards incorporate NZ Banking Data API Specification v2.3.3, as well as the related security profile and operational standards, with targeted modifications to ensure consistency with the Customer and Product Data Act.
Accredited requestors and data holders must comply with the standard as a condition of participation in regulated open banking. MBIE will monitor and enforce compliance.
Payments NZ API Standards(external link) — Payments NZ
Operational Standards(external link) — Payments NZ
Disclaimer on the Payments NZ Standards(external link) — Payments NZ
Future open banking standards development
Open banking standards will continue to evolve over time in response to implementation experience, participant feedback and opportunities to improve customer outcomes. This helps ensure standards remain practical, secure, interoperable, and fit for purpose as the open banking ecosystem matures.
MBIE works with participants and other contributors to identify issues, consider improvements, and explore future standards development.
The initial focus for regulated open banking is to establish a stable and consistent standards baseline. Early standards updates are expected to focus on resolving defects, clarifying requirements, addressing implementation issues, and improving consistency across the ecosystem.
As the market matures and initial implementation issues are addressed, the focus will shift towards larger enhancements, new functionality, and opportunities to support innovation, new use cases and improved customer outcomes.
This staged approach helps provide certainty for participants in the early years of regulated open banking, while creating a clear pathway for future growth and development. Future standards changes will be informed by participant feedback, implementation evidence, emerging use cases, and broader sector needs.
Regulated open electricity standards
Regulated open electricity is expected to be the next sector designated under the Consumer Data Right (CDR). Once the electricity regulations have been finalised, MBIE will work with industry to develop the supporting standards.