Google's Cloud Platform and Workspace provide a comprehensive suite of products, settings, and user guides for achieving the CDR accreditation.
The Consumer Data Right (CDR) is hyped as the railway lines or core infrastructure for the future of Australia's tech industry. Open Banking is the industry moving first - requiring the banks to make consumer data available and free to use by third-party services. This is subject to consumer consent and accreditation of the third-party services to verify they meet the security requirements of the CDR.
Accreditation requires an independent audit and assurance report by a qualified provider, like AssuranceLab & A-LIGN. This assurance requirement is one of the major barriers to participating in the CDR, with high costs and effort involved. It's been criticised for causing slow onboarding of Accredited Data Recipients (ADRs), with only a handful of accreditations nine months after the CDR went live in July 2020.
Like all standards, the path to compliance gets faster, easier and cost-effective over time. The ecosystem of service providers and knowledge grows to provide better solutions and clarity of the requirements. The CDR clearly describes the "what" (is required), but not the "how". This article explains the "how" for aspiring data recipients using Google's Cloud Platform and Workspace product suites.
For the purposes of implementing and auditing the required security practices, we split them into four types or levels that these practices are implemented and managed:
There are four high-level steps to implement your environment and security practices to meet the CDR requirements with Google products:
To get started, download our white-paper with the full list of CDR requirements mapped to Google and AssuranceLab knowledge base content.