> ## Documentation Index
> Fetch the complete documentation index at: https://redbark.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Consents

> Review and manage the Consumer Data Right consents that authorize Redbark to access your Australian bank data.

A CDR consent is a time-limited agreement that allows Redbark Sync to access your banking data. Each consent is tied to a specific bank and expires after 12 months.

<Info>
  This page applies to **Australian** bank connections under the Consumer Data Right. New Zealand connections are authorised through Akahu instead and have no 12-month expiry; you can withdraw access at any time by deleting the connection in Redbark or revoking it from your Akahu account. See [Connections](/docs/connections#new-zealand-bank).
</Info>

For background on how the CDR Representative model works and what we do and don't store, see [CDR overview](/docs/compliance/cdr-overview) and [Consent and data handling](/docs/compliance/consent-and-data).

## Where to view consents

Your Consents page lives at **[app.redbark.com/settings/consents](https://app.redbark.com/settings/consents)**.

To get there from inside the app:

1. Click your profile avatar in the top-right of any dashboard page.
2. Choose **Settings** from the menu.
3. Select the **Consents** tab in the left sidebar.

The page shows every consent you've given — active, expired, and withdrawn — with the bank, purpose, shared data categories, creation date, expiry date, and status.

## Managing consents

Consent management — including withdrawal — happens through **[Fiskil's consent dashboard](https://consents.fiskil.app/)**. Fiskil Pty Ltd (ADRBNK000246) is the accredited data recipient and manages the consent dashboard centrally to meet the regulatory content and disclosure requirements under the CDR Rules. Withdrawal at the bank revokes data access immediately; the change reaches Redbark when Fiskil delivers the corresponding webhook. On receipt, the consent record is marked withdrawn, any syncs on that connection are disabled, and the connection's CDR data (its accounts, stored tokens, and the connection record itself) is queued for deletion. Auditability comes from the consent history and a deletion tombstone log, not from retaining the data. This is intentionally as easy as giving consent in the first place, as required by [CDR Rule 4.16](https://www.legislation.gov.au/F2020L00094/latest).

## Consent cards

Each consent shows:

* **Bank name** and status icon
* **Purpose**: what the data is used for (e.g. "Transaction sync")
* **Status badge**: Active, Expired, or Withdrawn
* **Data shared**: the types of data included (e.g. Transactions, Accounts, Balances)
* **Created date** and **expiry date**

## Statuses

| Status        | Description                               |
| ------------- | ----------------------------------------- |
| **Active**    | Consent is valid and data can be accessed |
| **Expired**   | The 12-month consent period has ended     |
| **Withdrawn** | You have revoked the consent              |

## Expiring consents

Consents last 12 months from the date they were created. Redbark emails you an advance notice roughly 90 days before a consent expires so you have time to renew it. When a consent does expire, any syncs on that connection are disabled and the connection's CDR data (its accounts, stored tokens, and the connection record) is queued for deletion, the same as a withdrawal. To restore access you add a fresh connection (see [Re-consenting](#re-consenting)).

## Withdrawing consent

You can withdraw consent at any time through **[Fiskil's consent dashboard](https://consents.fiskil.app/)**. Data access is revoked at the bank straight away; on the next webhook from Fiskil, Redbark marks the consent withdrawn, disables any syncs on that connection, and queues the connection's CDR data (its accounts, stored tokens, and the connection record) for deletion. Auditability comes from the consent history and a deletion tombstone log, not from keeping the data. Data that has already been synced to your destinations is not deleted.

Using **Delete** from the three-dot menu on the [Connections](/docs/connections) page does exactly the same thing: it withdraws the consent, disables the affected syncs, and deletes the connection's CDR data. Either path fully removes the connection from Redbark.

## Re-consenting

To restore access after a consent expires or is withdrawn, add a new bank connection from the [connections](/docs/connections) page. This creates a fresh 12-month consent.
