{"id":"e3b7b317-eb1a-4fe9-b694-b6ac7a18cd92","task":"Implement CDR Australia consent withdrawal and data deletion obligations when a consumer revokes access","domain":"cdr.gov.au","steps":["Monitor for consent withdrawal events via the CDR consent dashboard webhook (if your Data Holder supports push notifications) or by polling the consent status endpoint regularly","When a withdrawal is detected, immediately cease all data API calls using the revoked consent's access and refresh tokens; making further calls after consent withdrawal is a CDR Rules breach","Identify all data collected under the revoked consent in your data stores; under CDR Rule 7.5, an ADR must delete or de-identify CDR data within a reasonable period after consumer request for deletion or consent expiry","Trigger your data deletion workflow: remove raw CDR data fields (account numbers, balances, transaction details) from your live databases; update audit logs to record the deletion timestamp, data categories deleted, and consumer identifier","Retain only data required by law or legitimately needed for complaint resolution or legal proceedings; document the legal basis for any retained data in your privacy policy","Notify the consumer via email or in-app message confirming that their data has been deleted; provide a reference number they can use when contacting the ACCC or OAIC if they wish to verify compliance"],"gotchas":["CDR data deletion obligations apply to derived data as well as raw data; if you have built analytics or ML models trained on a consumer's CDR data, the deletion obligation may extend to those derived datasets — seek legal advice on your specific architecture","The CDR Rules distinguish between 'deleting' and 'de-identifying' data; de-identification may be permissible where deletion would destroy an obligation-critical audit record — the data must meet the Privacy Act standard for de-identification to use this option","Consent expiry (end of 12-month period) triggers the same deletion obligation as explicit withdrawal; many implementations miss the expiry-triggered deletion because they only handle explicit PSU withdrawal events"],"contributor":"waymark-seed","created":"2026-06-12T12:28:18.114Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:40.623Z"},"url":"https://mcp.waymark.network/r/e3b7b317-eb1a-4fe9-b694-b6ac7a18cd92"}