WeMoney CDR Policy

1. ABOUT THIS POLICY

The Consumer Data Right (CDR), also known as "open banking", gives you the right to consent to organisations accredited by the Australian Competition and Consumer Commission (ACCC) accessing specified data about you (CDR data).

The CDR regime is designed to give Australian consumers greater choice and control over how their data is collected, used, and disclosed. It allows you, with your consent, to share your data for specific purposes with any organisation that is accredited under the CDR regime. You can also choose to send a copy of your own data to someone else, which is explained in Sections 6.2 and 8.

In this policy, references to "you" or "your" mean you as a user of our Services and a CDR consumer.

WeMoney Pty Ltd ACN 633 007 860, Australian Credit Licence 526330 (WeMoney or we or us) is an Accredited Data Recipient participating in the government's open banking scheme under the CDR regime.

WeMoney provides a smart money management service that connects all of your financial accounts in one place, tracks your overall financial health, provides details about your credit score, and offers information and tools to help you compare a range of products, credit providers and services. We may also tell you about products or promotions from our connected network of product providers. WeMoney provides its services via its website and mobile applications (the Services).

As part of delivering our Services, and in accordance with the consents you provide during the CDR consent process, we may collect, use, and share your CDR data for purposes including enrichment, transaction categorisation, personalised insights, and, where you have provided a de-identification consent, de-identifying certain CDR data and securely retaining it to train and improve our transaction categorisation models and for general research purposes.

This Consumer Data Right (CDR) Policy (CDR Policy) has been created in accordance with the requirements of Division 5 of Part IVD of the Competition and Consumer Act 2010, the Competition and Consumer (Consumer Data Right) Rules 2020 and the CDR Privacy Safeguard Guidelines (CDR Legislation). In this CDR Policy, we explain how we manage your CDR data, how you can access and correct your CDR data, how you can make a complaint, and how we de-identify, retain, and destroy your CDR data in line with your consents and the CDR regime.

2. CONSUMER DATA RIGHT INFORMATION

The CDR data we collect from you and hold is classified as your "required consumer data" within your banking records which may include:

  1. your contact details;
  2. occupation;
  3. account information;
  4. transaction records;
  5. specific information about the financial products you may have with an organisation; or
  6. CDR data that includes data that may be derived from the original account information and transaction details.

WeMoney as an accredited organisation under the CDR regime:

  1. allows you to give your consent to share your selected financial data for specific purposes so that we can provide our Services to you; and
  2. with your consent, is able to de-identify certain CDR data and use the resulting de-identified data for training and improving our transaction categorisation models and related personal finance tools, for general research purposes, and disclose the de-identified data in connection with those purposes as outlined in this policy.

We also set out in this CDR Policy how we will treat your data when it becomes redundant.

The great benefit is that you control and decide when to share your CDR data with us, what CDR data you share, and for how long.

You can also choose to let a third party view your CDR data inside the WeMoney platform, or send a copy of it to someone else. Those features work differently, and Sections 6.1 and 6.2 explain how each one works and how it ends.

As an accredited data recipient, we will only receive your CDR data with your consent.

We will also continue to manage your personal information in line with WeMoney's Privacy Policy and our obligations under the Privacy Act (1988). Please visit our Privacy Policy at www.wemoney.com.au/privacypolicy for further information.

3. HOW WE HOLD CDR DATA

WeMoney collects and holds your data that you provide to us as our consumer, which enables us and assists us to provide you with our Services.

This data that we hold and collect, may include data that is classified as "CDR data" upon us receiving it after you have given your consent as an accredited data recipient under the CDR regime.

Under the CDR regime a:

Data Holder: is the organisation that holds your data and upon your consent shares your data with an accredited data recipient, for e.g., your financial services provider.

Accredited Data Recipient: is an organisation accredited under the CDR regime that you have provided your consent to receive and use your CDR data from the Data Holder. WeMoney is an Accredited Data Recipient.

In this policy, "Accredited Data Recipient" and "Data Holder" have the meanings given in the Competition and Consumer Act 2010 (Cth).

When you provide your consent to an Accredited Data Recipient to collect and use your CDR data, it's important to know that you are then entering into an agreement with them.

At WeMoney, we will hold your data for a period of time as specified by you when you provide your consent or until you withdraw your consent. Once you withdraw your consent or the period of time that you have specified in your consent has expired, or we can no longer hold it under the CDR regime we will delete your CDR data that we hold about you, unless that data has been de-identified (see Sections 11 and 12).

Access you have allowed a third party under Section 6.1 works differently, and Section 6.1 explains how it ends.

WeMoney does not accept consumer requests to access additional voluntary products or consumer data that our Services does not already make available.

4. YOUR PRIVACY AND SECURITY

We will keep your CDR data in a cloud-based, or other types of networked or electronic storage centres. The security of your CDR data is important to us. We will take appropriate technical and organisational precautions to secure your CDR data as required under the CDR regime.

5.1 Sharing your CDR Data

You can choose to share your CDR data with WeMoney so we can provide you with our Services.

You will need to give your consent to WeMoney as an accredited data recipient to receive your CDR data from your nominated financial institution or financial services provider (Data Holder).

Prior to actioning your request to share your CDR data with WeMoney, we will:

  1. need to identify you first using our authentication methods;
  2. obtain your consent to sharing your CDR data from your nominated financial institution or financial services provider with WeMoney;
  3. ask you to choose which accounts/information you would like to share with WeMoney; and
  4. what period of time you want to share your CDR data with WeMoney.

IMPORTANT: Please note that your Data Holder will have their terms and conditions that you need to comply with when requesting to share your data with WeMoney.

5.2 Manage your CDR data sharing with your Data Holder

You can log in with your Data Holder and manage your data sharing to view your data sharing, manage your data sharing and stop your data sharing.

Please note that managing or stopping your CDR data sharing with your Data Holder does not affect any copies of your CDR data that you have previously exported or downloaded for your own use, because the CDR rules no longer apply to a copy you hold.

6. CDR DATA SHARING AND THIRD-PARTY ACCESS

WeMoney uses the entities listed below as its outsourced service providers (OSP) to provide the following services:

Name of Service Provider Description of Services provided by the Service Provider CDR Accreditation CDR Policy
Yodlee Inc (Yodlee) Manage its consent process with respect to accessing CDR data as an accredited data recipient, and to provide additional insights by enhancing merchant and payer identification and category details around your transactions. Accredited Data Recipient Yodlee CDR policy
Tata Consultancy Services Limited (TCS) (based in India) To provide customer servicing support, technology and infrastructure, and data processing services to Yodlee Inc. No Yodlee Service Provider and covered in Yodlee's CDR policy
Experian Australia Pty Ltd (Experian) (based in Australia) Provide transaction enrichment and categorisation services. These services assist us in enhancing the information we present to you about your transactions. No -
Mastercard Asia/Pacific Pte. Ltd. (Mastercard) Consent management, CDR connectivity, data aggregation and additional transaction enrichment services, which may include categorisation and income verification services. Accredited Data Recipient Mastercard CDR Policy
Mastercard Technologies LLC (based in the United States) Customer servicing support, technology and infrastructure, and data processing services to Mastercard. No Mastercard Service Provider and covered in Mastercard's CDR Policy
Mastercard International Incorporated (based in the United States) Customer servicing support, technology and infrastructure, and data processing services to Mastercard. No Mastercard Service Provider and covered in Mastercard's CDR Policy
Mastercard Asia/Pacific (Australia) Pty Ltd (based in Australia) Customer servicing support, technology and infrastructure, and data processing services to Mastercard. No Mastercard Service Provider and covered in Mastercard's CDR Policy
Finicity Corporation (based in the United States) Customer servicing support, technology and infrastructure, and data processing services to Mastercard. No Mastercard Service Provider and covered in Mastercard's CDR Policy
Finicity Technologies Private Limited (based in India) Customer servicing support, technology and infrastructure, and data processing services to Mastercard. No Mastercard Service Provider and covered in Mastercard's CDR Policy

Some of our OSPs, such as Mastercard, are also accredited data recipients (ADRs) under the CDR regime. However, in their role providing services to WeMoney, they do not act in that capacity. When processing or enriching your data under our instructions, they operate solely as OSPs under a CDR outsourcing arrangement with WeMoney. Their access and use of your CDR data is limited to what is permitted under that arrangement and your consent.

Where you have provided de-identification consent in the CDR consent process, certain OSPs (such as Mastercard and Yodlee) may create and retain de-identified datasets in accordance with that consent and the CDR regime. These de-identified datasets may be used for the purposes specified in your consent, including training and improving transaction categorisation models and for general research purposes, as described in Sections 8, 9, 10, and 11 of this policy.

We may, with your consent, disclose your CDR data to other Accredited Data Recipients.

You can also choose to send a copy of your CDR data to someone else, using the WeMoney app. When you do that, you are the person sharing your data, not WeMoney. Section 6.2 explains how it works and what it means for you.

Where a third party is not an Accredited Data Recipient, the handling of your data by that third party will not be subject to the CDR Privacy Safeguards. The website www.cdr.gov.au gives you more information regarding the accreditation process.

6.1 Letting Someone View Your CDR Data in WeMoney

You can use the WeMoney app to let a third party you choose view some of your CDR data inside the WeMoney platform. You decide whether to do this, and who can view your data. We decide which of your CDR data is included, and we show you a summary of it before you choose. You do not have to let anyone view your data to keep using our Services, and you can decline at any point before you allow access.

Before you allow access, we will show you:

  • who will be able to view your data;
  • a summary of what you are sharing, including the accounts and the date range it covers; and
  • how long they will be able to see it, which is never more than 30 days.

When you allow access:

  • your CDR data stays in WeMoney. The third party can view it within the WeMoney platform, and we do not send them a copy;
  • we continue to hold your CDR data, and the CDR Privacy Safeguards continue to apply to it; and
  • anything the third party records from what they see is handled under their own privacy obligations, such as the Privacy Act 1988 (Cth). You should check their privacy policy.

Access lasts for up to 30 days and then ends automatically. Only allow access if you are comfortable with the third party seeing that data for the whole period we show you.

6.2 Sending Your CDR Data to Someone You Choose

You can use the WeMoney app to send specified CDR data to one or more third parties or third-party applications that you choose. You decide whether to do this, and who receives your data. You do not have to share anything to keep using our Services, and you can decline at any point before you send.

Before you send, we will clearly tell you:

  • who each third party is;
  • the specific CDR data that will be sent;
  • what it is being sent for.

When you choose to send your CDR data this way:

  • Once your data reaches a third party who is not accredited under the Consumer Data Right regime, the CDR Privacy Safeguards no longer apply to how that third party handles it.
  • The third party's own privacy policy and the laws that apply to them will govern how they handle your data. We recommend you read the third party's privacy policy before you decide to send.
  • The third party may be located in Australia or overseas.

We record each send in our CDR audit logs.

The CDR data we still hold remains protected. Sending a copy to someone you choose does not change our obligations for the data that stays with us: it is still CDR data, and the CDR Privacy Safeguards continue to apply to it, including our obligations to keep it secure and to destroy or de-identify it when it is no longer needed.

7. HOW YOU CAN ACCESS YOUR SHARED CDR DATA WITH WEMONEY

CDR data that we have received will be made available to you securely via our Services. In addition, WeMoney allows you to update specific CDR data such as account holder information securely via our Services. Please note that for any data updates to other organisations that are Data Holders you will need to contact them directly to correct and update your CDR data.

You can log in to the WeMoney Services to view your data sharing, manage your data sharing, and stop your data sharing with us. Access you have allowed a third party under Section 6.1 works differently, and Section 6.1 explains how it ends.

7.1 Correcting your CDR data

If you think CDR data we hold about you is wrong, out of date, incomplete, irrelevant or misleading, you can ask us to correct it. Email us at hello@wemoney.com.au or contact us through the Services.

We will take reasonable steps to correct it, and we will respond within a reasonable period. If we correct your CDR data we will tell you, as described in Section 14. If we decide not to correct it, we will tell you why.

Some of your CDR data comes to us from your Data Holder and we cannot change it at its source. Where that is the case we will tell you, and you will need to ask your Data Holder to correct it with them.

Where you have provided a de-identification consent in the CDR consent process, some of your CDR data may be de-identified and retained in accordance with that consent. Once your data has been de-identified, it can no longer be used to identify you and will not be available to viewed, updated, or deleted as your CDR data will not be able to be linked to you. For more information, see Sections 8, 10, and 11.

8. EXPORTING OR DOWNLOADING YOUR CDR DATA

You may ask us to export or make available a copy of your CDR data in a downloadable or otherwise accessible format. This includes any feature within the WeMoney Services that allows you to download or export your bank transactions, account information, or other data that may originally have been obtained as CDR data.

When you request an export or download:

  • we will generate a copy of, or a document prepared from, the CDR data we hold about you, in a format that can be accessed, downloaded or stored outside our accredited CDR data systems as directed by you;
  • we will make that copy available to you outside our accredited CDR data systems; and
  • we will not keep a copy of the export after we make it available to you.

Once exported or downloaded, the CDR rules no longer apply to that copy. It is personal information that you control. You may choose to store, use, or share that exported information with third parties for your own purposes.

8.1 Your responsibility for exported or downloaded data

Any use or disclosure of exported or downloaded data is your responsibility.

Other than to the outsourced service providers listed in Section 6, WeMoney does not disclose your CDR data to third parties who are not accredited under the Consumer Data Right regime. Where you send your CDR data to someone you choose under Section 6.2, or give someone access to information you have exported or downloaded, that sharing is undertaken by you and is outside the scope of the CDR regime.

WeMoney does not oversee or control how any third party handles exported or downloaded information you choose to provide to them.

8.2 Exporting or downloading and your consents

Exporting or downloading your CDR data does not affect your existing consent arrangements or your ability to withdraw consent at any time.

8.3 Sharing exported or downloaded data with third parties

You may choose to provide exported or downloaded information to a third party (such as an adviser, accountant or broker). This activity is not a disclosure of CDR data by WeMoney, because it is you who provides the information, not us.

If a third party accesses exported or downloaded information:

  • they do so under your authority;
  • their handling of that information is governed by their own privacy and security obligations; and
  • WeMoney does not endorse, manage, or control their use of that information.

9. HOW WE USE YOUR CDR DATA

WeMoney offers its Service online, which enables users to manage their personal finances. Features include account aggregation of Australian bank accounts, calculating a user's net worth, providing insights into income and spending, defining and tracking savings goals, and participating in the WeMoney community.

WeMoney uses your data to deliver its Services to you and to improve the overall service quality in the long-term. Preparing a portable copy of your CDR data at your request does not constitute a use of CDR data for our own purposes; it is an action taken under your instruction to provide you with a copy of your data outside our accredited CDR data systems.

As part of delivering our Services, and in accordance with the de-identification consent you provided during the CDR consent process, certain transaction data is de-identified and processed using our categorisation algorithms. These de-identified datasets may be securely retained and used to train and improve our models that support transaction categorisation models, budgeting tools, and other personal finance insights.

We will only collect and use the CDR data that is reasonably needed to provide our Services to you, including the de-identification and retention of selected transaction data for these purposes.

We may also use your data that has been de-identified or becomes redundant as set out in section 11 (De-identified or Redundant Data).

10. DATA ENHANCEMENT

WeMoney enhances your CDR data to provide more meaningful and personalised financial insights. This involves identifying the parties to your transactions (such as merchants and payers) and assigning categories to your income and expenditure. Enrichment helps us deliver features like spending analysis, income and expense tracking, and selecting which products and offers we show you.

We also use enriched data to select which loan and credit offers we show you, based on your transaction patterns and income insights. This helps us decide which information to put in front of you and improve the personalisation of our Services.

We personalise which offers you see. We do not advise you on whether a product is right for you, and showing you an offer is not a recommendation that you take it up. Where we provide credit assistance, we do so under our Australian Credit Licence 526330.

Enrichment may be performed by WeMoney directly or by our outsourced service providers (OSPs). Where enrichment is performed by an OSP, it is applied only to CDR data that the provider has either collected on our behalf (e.g. Mastercard and Yodlee) or that WeMoney has shared with them in accordance with your consent and the CDR regime (e.g. Experian).

Where enrichment results in de-identified datasets being created, and you have provided de-identification consent in the CDR consent process, those de-identified datasets may be securely retained and used in accordance with Sections 11 and 12 of this policy.

For more information about third-party roles in enrichment, see Section 6. For more information about how de-identified or redundant data is handled, see Sections 11 and 12.

10.1 Mastercard

As an OSP of WeMoney, Mastercard collects CDR data on our behalf and provides additional enrichment services, which may include categorisation and income verification services. This enables WeMoney to deliver insights about the income sources that have been identified from your transaction data, your spending and your overall financial behaviour. This enrichment is applied only to the CDR data collected by Mastercard as our OSP. WeMoney then uses these categorised outputs, along with other internal processing, to generate insights and deliver enhanced services. Where enrichment produces de-identified datasets, these may be retained in de-identified form in accordance with your de-identification consent (see Sections 11 and 12).

10.2 Yodlee

Yodlee provides transaction categorisation and assists with account connectivity as an OSP appointed by WeMoney. Where Yodlee collects your CDR data on our behalf, it applies enrichment by identifying merchants and payers and assigning categories to the transactions. WeMoney uses this categorised data to produce insights about your financial situation. Where enrichment produces de-identified datasets, these may be retained in de-identified form in accordance with your de-identification consent (see Sections 11 and 12).

For more information about how redundant or de-identified data is handled following enrichment, see Sections 11 and 12.

10.3 Experian

WeMoney may share your CDR data with Experian to provide transaction enrichment and categorisation services. Experian processes this data and returns the categorised outputs to WeMoney, which we then use to generate insights about your spending and income.

11. DE-IDENTIFIED OR REDUNDANT DATA

This section describes how WeMoney handles your CDR data when it becomes redundant or is de-identified in the course of providing our Services.

11.1 De-identified Data

During the consent process, we may also seek your consent to de-identify certain CDR data and use the resulting de-identified data for:

  1. our general research purposes;
  2. training and improving our transaction categorisation models and related personal finance tools; and
  3. disclosing the de-identified data in connection with our general research purposes.

Once your data has been de-identified it can no longer be linked to you, so we do not delete it when your CDR data becomes redundant. It continues to be held in de-identified form.

For the purposes of this section, "general research purposes" includes providing feedback to the ACCC and participants of various data standard workgroups regarding WeMoney's CDR connection statistics, using high level de-identified data for statistics about CDR connections in WeMoney press releases, and identifying opportunities for improvement in how we collect, handle and use CDR data to deliver better Services to you.

11.2 Redundant Data

Any CDR data that we no longer need for the purposes as disclosed in this policy and for which we have no other lawful basis under the CDR regime to retain, will be treated as redundant data.

For data accessed via Mastercard:
Redundant CDR data will be deleted. Note however that where you have provided de-identification consent in the CDR consent process and your CDR data has been de-identified in accordance with that consent, it may be retained in accordance with Sections 11 and 12.

For data accessed via Yodlee:
During the consent process, you may choose to have your redundant CDR data deleted. If you do not make a deletion choice, we may either delete or de-identify it at our discretion. Please note that once your CDR data has been de-identified, it can no longer be deleted upon expiry or revocation of your consent, as it will no longer be able to be used to identify you as an individual. In such cases, the data will continue to be retained in its de-identified form.

12. Handling of De-identified Data by Third Parties

This section describes how third-party outsourced service providers (OSPs) may handle de-identified data after completing their services for WeMoney.

Some of our OSPs may perform de-identification of CDR data as part of providing enrichment, categorisation, verification, or other processing services. Where you have provided de-identification consent in the CDR consent process, an OSP may, in accordance with that consent and the CDR regime, securely retain de-identified datasets for the purposes specified in your consent, including training and improving transaction categorisation models and related personal finance tools, and for general research purposes (such as aggregated analysis, reporting, and identifying ways to improve their services).

These practices apply whether the CDR data was originally collected by the service provider on WeMoney's behalf or was shared with them by WeMoney under a CDR outsourcing arrangement.

Before any data set is retained, it must be de-identified so that no one is identifiable, or reasonably identifiable, from it or from other information anyone holds. That means removing personal information and any transaction attributes that could reasonably be used, alone or in combination with other information, to re-identify you.

WeMoney requires that where our OSPs retain de-identified data sets, they may do so only on these conditions:

  • the data sets must not be re-identified; and
  • they are retained solely for the purposes permitted by your consent.

13. WHERE YOUR CDR DATA IS STORED AND ACCESSED FROM

We store your CDR data in Australia, in data centres operated for us by Amazon Web Services. Those data centres are covered by Amazon Web Services' certification to ISO/IEC 27001, the international standard for information security management, and by its System and Organization Controls reporting. Those certifications are held by Amazon Web Services, not by WeMoney.

We keep your CDR data stored securely and encrypted in electronic form in accordance with this policy, the CDR regime and WeMoney's Privacy Policy.

Where your CDR data is accessed or processed from overseas, for example by certain OSPs listed in Section 6, such access will occur only in accordance with the CDR regime (including the Privacy Safeguards). All overseas access is subject to contractual and technical safeguards, and our obligations under the CDR regime continue to apply to your CDR data wherever it is accessed from.

Some of the outsourced service providers listed in Section 6 are based in, or access your CDR data from, the United States and India. Their countries are shown in the table in Section 6.

Where you choose to send your CDR data to a third party under Section 6.2, that third party may be located overseas. If that happens:

  • the overseas recipient may be subject to different privacy protections;
  • the CDR Privacy Safeguards will not apply to how that overseas third party handles your data; and
  • where it is practicable to do so, we will tell you the country the recipient is located in before you send.

14. HOW WE NOTIFY CONSUMERS

On several occasions, you will receive notifications via the Services. Such notifications will include:

  1. relevant lifecycle events regarding your CDR data (which includes when you set up, amend, stop sharing and where your CDR data sharing arrangement expires);
  2. requesting your consent to use your CDR data;
  3. the withdrawal of your consent;
  4. the collection of your CDR data, i.e., when updating your financial transactions;
  5. if you request and we correct your CDR data; and
  6. if our CDR accreditation is surrendered, suspended or revoked.

You can withdraw your consent authorisation to share your CDR data with or by WeMoney at any time via the Services or simply by letting us know by email that you are withdrawing your consent. Our email address to withdraw consent is hello@wemoney.com.au.

You may also withdraw your consent by:

  1. disconnecting an individual bank account within the Services or by withdrawing your consent remotely via your financial institution; or
  2. by deactivating your WeMoney account altogether.

Once WeMoney receives your consent withdrawal in any form, we will, in accordance with the CDR regime, permanently delete your CDR data from our systems as soon as practicable and in any event no later than 30 days of receiving your request, unless it has been de-identified in accordance with your de-identification consent you provided in the CDR consent process, and is retained as described in Sections 11 and 12 of this policy.

Once your CDR data is permanently deleted you will not be able to access it unless you provide a new consent for us to receive your CDR data.

Where you have allowed a third party to view your CDR data within the WeMoney platform under Section 6.1, that access runs for up to 30 days and then ends automatically. Withdrawing your consent does not end it, and you cannot end it earlier. This means a third party may still be able to view your data for a period after you have asked us to stop holding it.

Sending a copy of your CDR data to someone you choose under Section 6.2 works differently. Once your data has been sent, it cannot be recalled, and we cannot control what the recipient does with it.

16. CONTACTING US OR MAKING A COMPLAINT

16.1 Contacting Us

WeMoney is here to help. If you want to know how we hold and manage your CDR data or you want to request a copy of your CDR data please contact us via either our Services, call us on 1300 629 510 or email us at hello@wemoney.com.au or by writing to us at WeMoney Pty Ltd, Level 1, 63-73 Ann Street, Surry Hills, NSW 2010, Australia.

If you have questions about exported or downloaded copies of your data, please note that we do not keep a copy once we have made it available to you. The copy you hold is yours to manage.

16.2 Making a Complaint to Us

If you are concerned about how we have handled your CDR data or you want to make a complaint or provide us with any feedback, please email us at complaints@wemoney.com.au, or contact us on the other details outlined in section 16.1 above. We will attempt to the best of our abilities to resolve any issue that you may have.

In order for us to assist you, please include your full name, email and contact details, as well as a preferred contact method in your email to us. We may ask for additional information to identify and verify you. Please note a WeMoney representative will never ask you for your log-in account information such as your password via phone or email.

We will do our best to:

  1. try and resolve your complaint immediately, if possible;
  2. resolve your complaint within 5 business days. If this isn't possible, we will confirm the outcome with you in writing. We will aim to resolve your complaint within 30 days. If we can't meet these timeframes, we will explain to you why and will provide to you an expected date for the outcome of your complaint. We will keep you informed of progress; and
  3. we will explain to you about our decision with respect to your complaint and notify in writing for all complaints that are not resolved within 5 business days.

If you are not satisfied with the final outcome, you may choose to lodge a complaint with the Australian Financial Complaints Authority (AFCA). AFCA provides a free and independent dispute resolution service for individuals and small business consumers who are unable to resolve their complaints directly with WeMoney.

Australia Financial Complaints Authority
Online: www.afca.org.au
Email: info@afca.org.au
Phone: 1800 931 678
Mail: GPO Box 3, Melbourne, VIC 3001

You may also raise any CDR concerns directly with the Office of the Australian Information Commissioner (OAIC). OAIC acts as an impartial third party when investigating and resolving a complaint in relation to the handling of your CDR data. You can contact the OAIC on:

Office of Australian Information Commissioner
Mail: GPO Box 5218, Sydney, NSW 2001
Phone: 1300 363 992
Online: www.oaic.gov.au
Email: enquiries@oaic.gov.au

17. NOTIFIABLE DATA BREACHES

From February 2018, the Privacy Act includes a new Notifiable Data Breaches scheme (NDB) which requires us to notify you and the Office of the Australian Information Commissioner (OAIC) of certain data breaches and recommend steps you can take to limit the impacts of a breach (for example, a password change).

The NDB scheme requires us to notify you about a data breach that is likely to result in serious harm to affected individuals. There are exceptions where notification is not required. For example, where we have already taken appropriate remedial action that removes the risk of serious harm to any individuals.

If we believe there has been a data breach that impacts your CDR data and/or your personal information and creates a likely risk of serious harm, we will notify you and the OAIC as soon as possible and keep in close contact with you about the nature of the breach, the steps we are taking and what you can do to reduce the impacts to your privacy. If we believe there has been an information security incident, we will notify the Australian Cyber Security Centre (ACSC) as soon as practicable.

If you believe that your CDR data or personal information has been the subject of a data breach, you can contact us using the contact details outlined in Section 16.1 above.

18. AVAILABILITY

This CDR Policy is available electronically by selecting "Settings", then "CDR Policy" within our Services. It is also available on the WeMoney website by visiting www.wemoney.com.au/policies/cdr-policy, and on request by contacting us at hello@wemoney.com.au.

We reserve the right to change this CDR Policy, at any time and when we do, we will post the current version on our website and will be available in "Settings", then "CDR Policy" within our Services.

The revised CDR Policy shall apply from the date of publication of the revised CDR Policy on our website, and is made available in "Settings", then "CDR Policy" within our Services.

We will not file a copy of the CDR Policy specifically in relation to each user or consumer and, if we update the CDR Policy, the version to which you originally agreed may no longer be available on our WeMoney website or made available in "Settings", then "CDR Policy" within our Services. We recommend that you consider saving a copy of the CDR Policy for future reference.

This CDR Policy is Version 6.5 dated 29 September 2026.