> ## Documentation Index
> Fetch the complete documentation index at: https://docs.redbark.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Consents

> View your Consumer Data Right (CDR) consents

A CDR consent is a time-limited agreement that allows Redbark Sync to access your banking data. Each consent is tied to a specific bank and expires after 12 months.

For background on how the CDR Representative model works and what we do and don't store, see [CDR overview](/compliance/cdr-overview) and [Consent and data handling](/compliance/consent-and-data).

## Where to view consents

Your Consents page lives at **[app.redbark.com/settings/consents](https://app.redbark.com/settings/consents)**.

To get there from inside the app:

1. Click your profile avatar in the top-right of any dashboard page.
2. Choose **Settings** from the menu.
3. Select the **Consents** tab in the left sidebar.

The page shows every consent you've given — active, expired, and withdrawn — with the bank, purpose, shared data categories, creation date, expiry date, and status.

## Managing consents

Consent management — including withdrawal — happens through **[Fiskil's consent dashboard](https://consents.fiskil.app/)**. Fiskil Pty Ltd (ADRBNK000246) is the accredited data recipient and manages the consent dashboard centrally to meet the regulatory content and disclosure requirements under the CDR Rules. Withdrawal at the bank revokes data access immediately; the change reaches Redbark when Fiskil delivers the corresponding webhook. On receipt, the consent record is marked withdrawn, any syncs on that connection are disabled, and the connection's CDR data (its accounts, stored tokens, and the connection record itself) is queued for deletion. Auditability comes from the consent history and a deletion tombstone log, not from retaining the data. This is intentionally as easy as giving consent in the first place, as required by [CDR Rule 4.16](https://www.legislation.gov.au/F2020L00094/latest).

## Consent cards

Each consent shows:

* **Bank name** and status icon
* **Purpose**: what the data is used for (e.g. "Transaction sync")
* **Status badge**: Active, Expired, or Withdrawn
* **Data shared**: the types of data included (e.g. Transactions, Accounts, Balances)
* **Created date** and **expiry date**

## Statuses

| Status        | Description                               |
| ------------- | ----------------------------------------- |
| **Active**    | Consent is valid and data can be accessed |
| **Expired**   | The 12-month consent period has ended     |
| **Withdrawn** | You have revoked the consent              |

## Expiring consents

Consents last 12 months from the date they were created. Redbark emails you an advance notice roughly 90 days before a consent expires so you have time to renew it. When a consent does expire, any syncs on that connection are disabled and the connection's CDR data (its accounts, stored tokens, and the connection record) is queued for deletion, the same as a withdrawal. To restore access you add a fresh connection (see [Re-consenting](#re-consenting)).

## Withdrawing consent

You can withdraw consent at any time through **[Fiskil's consent dashboard](https://consents.fiskil.app/)**. Data access is revoked at the bank straight away; on the next webhook from Fiskil, Redbark marks the consent withdrawn, disables any syncs on that connection, and queues the connection's CDR data (its accounts, stored tokens, and the connection record) for deletion. Auditability comes from the consent history and a deletion tombstone log, not from keeping the data. Data that has already been synced to your destinations is not deleted.

Using **Delete** from the three-dot menu on the [Connections](/connections) page does exactly the same thing: it withdraws the consent, disables the affected syncs, and deletes the connection's CDR data. Either path fully removes the connection from Redbark.

## Re-consenting

To restore access after a consent expires or is withdrawn, add a new bank connection from the [connections](/connections) page. This creates a fresh 12-month consent.
