Canada Gazette, Part I, Volume 160, Number 26: Consumer-Driven Banking Regulations

June 27, 2026

Statutory authority
Consumer-Driven Banking Act

Sponsoring department
Department of Finance Canada

REGULATORY IMPACT ANALYSIS STATEMENT

(This statement is not part of the Regulations.)

Executive summary

Issues: When making purchases or carrying out banking tasks, consumers, including individuals and businesses, generate a stream of information based on their transactions. In Canada, this financial data is predominantly held and controlled by incumbent financial institutions. Recognizing the value of leveraging this data, financial technology businesses (fintechs) have developed applications that utilize consumers’ financial records to provide innovative products and services. Canada has not yet implemented a consumer-driven banking framework to ensure that this financial data is shared securely and with adequate oversight. A lack of requirements and supervision for these activities stifles innovation and competition, as well as poses significant security, liability, and privacy risks for Canadians and Canadian businesses who must provide their banking credentials to fintechs to access these services.

Description: The Consumer-Driven Banking Act (the Act), which received royal assent in March 2026, and the proposed Consumer-Driven Banking Regulations (the proposed Regulations), introduce a secure framework overseen by the Bank of Canada that enables Canadian individuals and businesses to share their financial data with accredited service providers of their choice. The proposed Regulations include requirements related to accreditation, security, national security, authentication and consent, reporting, record keeping, framework transparency, technical standards, assessments, and violations. The proposed Regulations also include the timelines and information requirements to support the national security review process related to the Minister of Finance’s national security authorities under the Act.

Rationale: The proposed Regulations are required to support the implementation of the Act. The objectives of the consumer-driven banking framework, informed by the Act and proposed Regulations, are to promote competition and innovation in the financial sector, improve financial outcomes for Canadian consumers and businesses, ensure that consumers can share their data securely and are protected while doing so, and strengthen Canada’s position in the global digital economy. The inclusion of national security authorities under the Act and the proposed Regulations supports the integrity of the financial system, making it more safe and secure for consumers to share financial data.

The development of Canada’s consumer-driven banking framework was informed by lessons learned from leading jurisdictions that have implemented successful open banking frameworks, as well as extensive stakeholder engagement involving financial institutions, fintechs, provincial governments, consumer groups, academics, and domestic policy experts. Together, this process provided the evidence base for adopting a government-led, legislated framework overseen by the Bank of Canada, with a role for provincial and territorial governments in overseeing provincially regulated entities that opt in to the framework in appropriate circumstances.

The proposed Regulations would result in an estimated total cost of $457.7 million total present value (TPV) over a 10-year period. The estimated monetized benefits of the proposed Regulations are $13.2 billion TPV over a 10-year period. All Canadians would benefit from the increased access to innovative financial services and economic growth driven by the implementation of the framework. Thus, preliminary estimates of monetized benefits are illustrative and non-exhaustive, and many of the benefits cannot be quantified at this time.

Issues

When making purchases or carrying out banking tasks, consumers, including individuals and businesses, generate a stream of information based on their transactions. In Canada, this financial data is predominantly held and controlled by incumbent financial institutions, including the country’s largest banks. Recognizing the value of leveraging this data, financial technology businesses (fintechs) have developed applications that utilize consumers’ financial records to provide innovative products and services. However, the current lack of regulatory framework overseeing these activities has limited innovation and competition, leading to untapped potential across the Canadian digital economy.

About nine million Canadians currently access financial data sharing services by providing their confidential banking credentials in a process known as screen scraping. This unregulated and technologically unsecure practice can negatively impact consumers by posing increased security, liability and privacy risks, leaving them without recourse if something goes wrong, such as a data leak of their personal or financial information. The absence of a framework to screen for hostile actors seeking to target consumer data sharing technologies for their own objectives poses a threat to national security and puts Canadians at risk.

To promote financial sector competition, establish secure and efficient financial data sharing, and address the risks posed by screen scraping, the Government introduced the Consumer-Driven Baking Act (the Act), which received royal assent in March 2026. The Act introduces a new supervisory regime administered by the Bank of Canada for entities participating in the framework, including federal and provincial financial institutions, fintechs, and other businesses, as well as third-party service providers, which may assist participating entities by carrying out certain activities on their behalf. The Act also provides the Minister of Finance with authorities to address national security risks posed by participating entities and third-party service providers.

The proposed Consumer-Driven Banking Regulations (the Regulations) are required to bring the Act into force and would prescribe key elements and criteria for entities to become accredited by the Bank of Canada, comply with the Act, and for the Bank of Canada to promote compliance with the Act and Regulations.

Background

Consumer-driven banking, also known as open banking, refers to secure frameworks that enable individuals and businesses to share their financial data with approved service providers of their choice. This is achieved through robust regulatory requirements and oversight of businesses that use application programming interfaces (APIs), a type of technology that provides a more secure connection between entities, to share consumer financial information with consent. Sharing financial information in this way gives consumers greater control over their data while promoting a competitive, innovative, and secure financial sector and digital economy.

In recognition of the merits of safe and secure financial data sharing, governments across the globe, including those in Australia, New Zealand, Brazil, the European Union, India, and the United Kingdom, have implemented systems of open banking. Certain jurisdictions, such as Australia, have gone one step further and adopted an economy-wide approach to data sharing that began with open banking, grew to energy, and will expand to other sectors, such as telecommunications.

As part of a broader effort to enhance rights and protections for consumers in a digital economy, the Government of Canada announced a Review into the Merits of Open Banking in Budget 2018. The Advisory Committee on Open Banking (Advisory Committee) was appointed to guide the review. In 2019, Finance Canada released a consultation paper exploring whether open banking should be considered for Canada. Following its work, the Advisory Committee concluded that open banking could deliver benefits to consumers and found that a framework with established rules would manage risks and support a more innovative and competitive financial services sector.

The Advisory Committee was then reappointed by the Government to conduct a review into the implementation of open banking in Canada, which resulted in a final report in 2021. The Advisory Committee identified common rules (privacy, security, and liability), accreditation, and technical standards as the core elements necessary for a functioning open banking system in Canada. The report made 34 recommendations, one of which was the appointment of an ’Open Banking Lead’ to convene industry to develop accreditation criteria and common rules. The Advisory Committee also recommended that the initial scope be limited to read access functions (i.e. providing only for viewing and sharing of data between accredited parties), and that the system be built to allow the scope to be expanded to include new types of data and “write access” functions (i.e. the ability to initiate a financial transaction or other action from an account, such as opening or closing the account) once the system is established.

In early 2022, the Government appointed Abraham Tachjian, a Canadian lawyer with international banking experience, as the Open Banking Lead (the Lead) with a mandate to develop a made-in-Canada regime based on the recommendations in the Advisory Committee’s final report. The Lead established four working groups on privacy, security, accreditation, and liability with balanced representation from industry, consumer groups, and government regulators. The Lead also established a steering committee to discuss issues related to governance and technical standards. In late 2023, the Lead concluded his term by providing a recommendation to the Minister that the Government move forward, through legislation, to implement a system of open banking, with a phased approach to scope (data, participants, and functionality) and adopt a single technical standard and timeline for phasing out screen scraping.

In addition to studying the benefits of financial innovation, including open banking frameworks, the Government of Canada has continued to evaluate and assess the evolving financial sector risk environment shaped by new technologies and geopolitical events. For instance, the Office of the Superintendent of Financial Institutions’ (OSFI) 2025-2026 Annual Risk Outlook indicates that state actors and state-sponsored actors may target Canadian institutions for financial gain, to advance their political objectives, and disrupt the functioning of Canada’s financial infrastructure and economy. Canada’s consumer-driven banking framework seeks to mitigate these risks by providing the Minister of Finance with adequate national security authorities.

The Government introduced the first part of the consumer-driven banking legislation through the Budget Implementation Act, 2024, No. 1. The legislative framework was completed through Budget Implementation Act, 2025, through the inclusion of provisions for accreditation and common rules that address security, national security, liability, and consent. Budget Implementation Act, 2025 also reinforced the importance of data-driven innovation and the role it plays in competition through amendments to the Personal Information Protection and Electronic Documents Act (PIPEDA) that enshrined an economy-wide right to data portability for all Canadians in sectors that develop secure and interoperable frameworks. Consumer-driven banking will be a first iteration of such a framework.

Further to announcing the completion of the consumer-driven banking legislative framework, Budget 2025 also announced the Government’s intention to move quickly to advance regulation to implement the framework, and to undertake consultation and policy work to advance a second phase of consumer-driven banking that considers broader scope and functionality, including write access. It also announced delegation of oversight of the Act to the Bank of Canada, building on its oversight of payment service providers (PSPs) under the Retail Payment Activities Act (RPAA).

The RPAA introduced a retail payment supervisory regime for PSPs, such as payment processors and digital wallets. Provisions requiring PSPs to register with the Bank of Canada came into force in November 2024 while substantive requirements of the RPAA — establishing operational risk management and funds safeguarding frameworks — came into force in September 2025. Leveraging the Bank of Canada’s existing resources and expertise will enable the Government to advance its goals for consumer-driven banking quickly and streamline processes for participants of both regimes.

Consumer-Driven Banking Act

The core elements of Canada’s consumer-driven banking framework (the framework) are set out in the Act, which establishes obligations falling broadly into the following categories: governance, scope, accreditation, common rules (consent, liability, security), national security, technical standards, framework transparency, and a prohibition on screen scraping.

Governance

To improve government efficiency and align with existing oversight for the RPAA, the responsibility for implementation and oversight of the Act is delegated to the Bank of Canada. To facilitate participation of provincially regulated financial institutions, the governance model is structured to allow provincial financial institutions, including credit unions and crown corporations that offer deposit-taking services to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.

To enhance federal, provincial and territorial collaboration, the Act authorizes the Minister of Finance to designate the supervision of certain legislative provisions to a provincial authority when certain criteria are met. The provincial authority will supervise the obligations and work with the Bank of Canada for necessary enforcement. The Act also establishes a federal, provincial and territorial advisory committee to advise on the implementation and evolution of the framework.

Scope

The consumer-driven banking framework’s scope is divided into three elements: (i) which entities can participate, (ii) the breadth of data sharing, and (iii) functionality. Participation in the framework will initially be mandated for specified large banks based on a threshold for retail volume. Remaining federally regulated financial institutions, as well as credit unions, crown corporations that offer deposit-taking services, PSPs registered under the RPAA, and other entities seeking accreditation, would be able to opt in, provided they meet the requirements for entry and demonstrate adherence to the technical standard and security specifications. Under the Act, all participating entities are required to share consumer-authorized in-scope data (including data related to deposit accounts, payment products, investment accounts, and lending accounts) and may not impose a charge for doing so, nor for obtaining, renewing or withdrawing consent. Derived data, defined as information about a consumer, product, or service that has been significantly enhanced by a participating entity to increase its usefulness or commercial value, is excluded from the Act. Framework functionality will be limited to “read only” access under phase one.

Accreditation

The Act provides the Minister of Finance the authority to mandate the participation of certain banks in the framework and sets out accreditation processes for other federally regulated financial institutions, provincially regulated financial institutions, RPAA registered PSPs, and other entities to ensure that only those that meet certain requirements can participate in the data-sharing ecosystem. The Act also requires participating entities that wish to outsource certain tasks related to consent management, authentication management, and movement of data to use accredited-third party service providers (ATPSPs) that meet applicable accreditation requirements. The Act requires the Bank of Canada to publish a list of all participating entities and ATPSPs in a central public registry.

Common rules

Common rules are established in the Act around consent, liability, and security for all participants. These rules include requiring consent and revocation processes that are clear, simple, and not misleading, establishing that liability flows with the data, and setting out clear security requirements. The Act also provides the Minister of Finance with the authority to designate an independent, not-for-profit, external complaints body overseen by the Bank of Canada to resolve consumer-driven banking complaints free of charge to the consumer. All participating entities must be a member of the external complaints body. The Act authorizes the Minister to exempt entities from this membership requirement, provided they are members of a recognized provincial equivalent.

National security

The Act provides authorities to the Minister of Finance to address risks related to national security that could be posed by participating entities and ATPSPs. The Minister will be able to review applicants and accredited entities and issue a directive to the Bank of Canada to refuse, suspend, or revoke access to the framework for national security reasons. The Minister may also require an undertaking from, or impose terms and conditions on, an applicant, participating entity, or ATPSP for national security reasons. These authorities align with existing financial sector statutes, such as the RPAA and the Bank Act.

Technical standards

The Act requires participating entities to implement a single technical standard set by a technical standards body to provide certainty to framework participants and supervisors. The technical standards body will be designated according to the factors and processes set out in the Act. The designation factors include being meaningfully Canadian; having a governance structure that is fair, open, and accessible, with independent decision making and an ability to exercise powers and act in a manner consistent with the objectives of the Act; and ensuring the standard itself is safe, secure, and interoperable. The Act also authorizes the Minister to consider any other factor deemed relevant and authorizes that regulations may be made to include additional criteria. The Act includes authorities for the Minister of Finance to designate and revoke the technical standards body, through a Ministerial Order, and other criteria to inform the assessment of candidates for said body.

Framework transparency

In order to foster transparency and trust, the Act requires the Bank of Canada to publish consumer-driven banking-related information to inform participating entities and the public. Regulations specifying the precise nature of the information to be published are not necessary for the operationalization of the framework, but may be advanced in the future subject to further consultation and engagement.

Prohibition of screen scraping

The Act includes a prohibition on screen scraping that is not required to operationalize the broader framework and will not be brought into force until broader consultation and policy development have taken place. The Department of Finance will continue to consult with stakeholders to determine an appropriate timeline for bringing the prohibition into force and parameters for the ban that would be articulated in regulation at a future date.

Objective

The goals of Canada’s consumer-driven banking framework, informed by the Act and proposed Regulations, are to promote competition and innovation in the financial sector, improve financial outcomes for Canadian consumers and businesses, ensure that consumers can share their data securely and are protected while doing so, and provide the Government with the information needed to protect Canadians and Canadian financial sector infrastructure from national security risks. In other countries, regulated frameworks have proven effective at achieving these policy goals by empowering consumers, enhancing data accessibility, and supporting new financial service providers and business models within an established regulatory framework informed by appropriate checks and balances.

The development of the consumer-driven banking framework, including the proposed Regulations, was guided by three public policy objectives:

Description

The proposed Regulations would operationalize the Consumer-Driven Banking Act, ultimately enabling consumers, including individuals and businesses, to securely share their financial data through an API to approved service providers of their choice. The specific requirements informing the proposed Regulations are set out below.

Data scope

The breadth of data sharing is broadly defined in the Act. It specifies that, at the request of a consumer, participating entities will be required to share both data provided by a consumer and product data related to deposit accounts (chequing and savings), payment products, investment accounts (registered and non-registered),footnote 1 and lending accounts (secure and unsecured).footnote 2 The proposed Regulations would provide further clarity regarding the scope of data that must be made available for sharing to consumers with regards to consumer profile data, account data, including balance and transaction data, and product data.

Proposed consumer profile data would include information provided by the customer in the context of account opening, identification, and verification (such as, but not limited to, name, address, date of birth, and employment information). Proposed account data for in-scope data sharing would include information identifying the accounts held by a consumer (such as, but not limited to, the number of accounts held, and identifiers or numbers used to identify those accounts), account agreement and product document information (such as, but not limited to, information outlining the contractual terms and conditions applicable to the consumer’s account), balance data (such as, but not limited to, the value held in, owing on, or otherwise associated with one or more accounts held by the consumer, including balances presented on periodic statements or bills), and transaction data (such as, but not limited to, the information relating to financial activity in respect of the account, including recent, pending, pre-authorized, and historical transactions). Finally, proposed product data would include information related to the financial products and services offered by participating entities to the consumer.

Accreditation

The Act provides for an accreditation process overseen by the Bank of Canada to ensure that only entities that meet certain requirements, in accordance with the proposed Regulations, can participate in the framework. Banks mandated to participate in the framework are not subject to the accreditation process.

The proposed Regulations set out criteria for four pathways of accreditation specific to applicant entity type that must be demonstrated through submitting required material to the Bank of Canada using the electronic system provided by the Bank of Canada. The Bank of Canada will develop and publish guidelines on accreditation application criteria and processes ahead of the Act’s coming into force. Accreditation criteria for each pathway include:

Regardless of accreditation pathway, all applicants would need to submit a prescribed accreditation fee to the Bank of Canada. The proposed Regulations set this fee at $2,500, to be adjusted for inflation and rounded to the nearest $100 on a yearly basis. There is also a separate annual assessment fee paid by all participating entities, as outlined in the section below.

The Bank of Canada will have the authority to deny, suspend, or revoke the accreditation status of any participating entity or third-party service provider (other than a mandated bank) and will be required to maintain a public registry of these decisions. The proposed Regulations would provide 30 days for applicants to request a review of a refusal to accredit and to participating entities and ATPSPs who have received a notice of intent to revoke their accreditation status. The Bank of Canada would be provided with 120 days to then provide a decision to the applicant or participating entity or ATPSP. The proposed Regulations provide the applicant or participating entity or ATPSP with 30 days to appeal the decision to federal court.

Accreditation is not a static obligation and there is no requirement for accredited entities to renew accreditation status once provided. Participating entities and ATPSPs would be required to keep the accreditation information up to date and continue to meet applicable accreditation requirements and criteria on an ongoing basis. Any changes to the accreditation requirements or information submitted in the course of applying for accreditation would require a notice of change to be submitted to the Bank of Canada, as described in the duties of participating entities and ATPSP sections below. In the case where a participating entity or ATPSP no longer meets the accreditation requirements, the Bank of Canada may issue a notice to suspend or revoke their accreditation status.

The proposed Regulations would specify that the public registry of participating entities and ATPSPs be updated in real time. The registry would include the name and contact details of each participating entity and ATPSP, including the date they were mandated to participate or were accredited, their status of accreditation (including suspension and revocation), and the contact information for the individual they have appointed to oversee complaints related to their participation in the framework. The registry would also include a functionality that other participating entities can use to access a developer portal to facilitate data sharing, and a list of activities offered by each ATPSP.

National security safeguards

The proposed Regulations related to national security support the Minister of Finance’s authorities. The national security provisions in the Act and proposed Regulations are modelled on and consistent with other financial sector statutes, such as the Bank Act and the RPAA.

The Act contains national security safeguards that enable the Minister to review accreditation applicants, participating entities, and ATPSPs for risks related to national security. Under any accreditation pathway, in accordance with the Act, all applicants would need to submit information necessary for national security purposes to the Bank of Canada. As set out in the proposed Regulations, this would include identifying information about the applicant, its owners, senior officers, directors, and other persons with significant influence over the applicant (including creditors and state-owned enterprises), information about personal data collection, use, and sharing with third parties, and information about relevant corporate and business relationships.

The proposed Regulations would provide the Minister with 60 days to decide to review an accreditation application for national security concerns and allow the Minister to extend the decision period for additional 60-day periods, if necessary. Should the Minister decide to proceed with a national security review, the proposed Regulations would specify that the review must be conducted within 180 days and that the period for conducting the review may be extended for additional 180-day periods at the discretion of the Minister. In accordance with the Act, if a national security review is required, the Minister would inform the Bank of Canada, which would in turn inform the applicant of the Minister’s decision. Should the Minister request additional information related to the national security review, the proposed Regulations would specify that the applicant would have 30 days to provide the requested information to the Bank of Canada.

Upon completion of the review, the Act provides that the Minister may issue a directive to the Bank of Canada to refuse an accreditation application submitted by a participating entity or ATPSP. The Minister may also require an undertaking from, or impose terms and conditions on, an applicant, participating entity or ATPSP for reasons related to national security.

Relatedly, the proposed Regulations would specify that an applicant, participating entity, or ATPSP would have 30 days to request a review of the Minister’s decision to direct the Bank to refuse accreditation or the Minister’s issuance of a notice of intent to direct the Bank to revoke accreditation.

Duties of participating entities

Once admitted to the framework, the Act provides that participating entities must fulfill various requirements to uphold consumer protection measures, maintain their accreditation status, demonstrate their compliance with the Act, and abide by common rules related to privacy and consent, liability, security, and integrity. The proposed Regulations would specify the requirements as set out in the Act related to the display of signs, notices, record keeping, annual reporting, common rules, and data sharing as follows:

Duties of ATPSPs

The Act provides that participating entities can enter a contract with an ATPSP to outsource prescribed activities while still maintaining overall liability for those activities. Nonetheless, to preserve the integrity of the framework, the Act requires ATPSPs to undertake duties both while they participate in the framework, as well as when they exit it. The proposed Regulations would further specify the requirements as set out in the Act as follows:

Technical standards body reporting

The Act requires the designated technical standards body to submit an annual report to the Bank of Canada to demonstrate that it remains compliant with the designation factors considered by the Minister. The annual report also provides the information necessary for the Bank of Canada to inform its advice to the Minister regarding the technical standards body. The proposed Regulations would require the annual report to include information about security features added to the standard and information relating to overall standard performance. The proposed Regulations would require the technical standards body to provide the Bank of Canada with any changes that were made and could be relevant to the body’s designation under the Act.

Evidentiary privilege

The Act provides a regulation-making authority to enable the Minister of Finance, the Governor of the Bank of Canada, and the Attorney General of Canada to use prescribed supervisory information as evidence during civil litigation and proceedings. The proposed Regulations divide the information into three categories based on the document’s objective. These categories include information issued or prepared by the Bank of Canada in connection with its supervision of consumer-driven banking activities; correspondence related to accreditation, notices, letters, and compliance agreements; and directions given to participating entities, ATPSPs, the external complaints body, or the technical standards body.

Assessment fees

Once the framework is operational, the Bank of Canada will recover the costs associated with the administration of the Act via assessments on participating entities, accredited third-party service providers, and the external complaints body. The proposed Regulations would include an annual assessment regime applicable to participating entities, ATPSPs, and the external complaints body; a tiered assessment formula for participating entities consisting of a base fee and a variable fee component linked to total asset value; and provisions governing assessments for ATPSPs and the external complaints body. The proposed Regulations would specify that participating entities would be required to report, on an annual basis, the information necessary for the Bank of Canada to administer both the fixed and variable portions of the assessment fee, including the participating entity’s total asset value as of December 31 for each calendar year. The framework is designed to allocate a greater share of costs to entities with larger asset bases, while limiting volatility and administrative burden for smaller participants and new entrants.

Violations

The proposed Regulations would designate which provisions of the Act and Regulations may be treated as violations, subject to administrative monetary penalties determined by the Bank of Canada, and that do not need to be treated as offences. The majority of the provisions would relate to the common rules or obligations that all participating entities must adhere to as part of their participation in the framework, such as those related to consent, authentication, disclosure of information, and reporting.

In accordance with the Act, the maximum penalty for a violation is $1,000,000 if the violation is committed by an individual and $10,000,000 if committed by a participating entity or ATPSP. The Act does not establish a minimum penalty for violations and the precise penalty issued by the Bank of Canada is left to its discretion as the supervisor.

Regulatory development

Consultation

The development of Canada’s consumer-driven banking framework, including the proposed Regulations, has benefited from extensive consultation with hundreds of industry stakeholders, including banks, credit unions, fintechs, and industry associations, as well as academics, civil society organizations, not-for-profit organizations, industry experts, federal government departments and agencies, provinces and territories, and other jurisdictions, including the United Kingdom and Australia.

Engagement on this topic began with Budget 2018, when the Government announced a review into the merits of open banking. As a first step, the Minister of Finance appointed the Advisory Committee on Open Banking to guide the review with support from a secretariat within the Department of Finance. The Advisory Committee was tasked with considering whether open banking would provide meaningful benefits to Canadians and delivering a report assessing the potential merits of open banking for Canada, with the highest regard for consumer privacy, security, and financial stability.

The Department of Finance and the Advisory Committee released its first consultation paper in 2019, A Review into the Merits of Open Banking, resulting in over 120 written submissions from industry stakeholders, including banks, fintechs, industry associations and federal government departments and agencies. Of the 120 submissions, those whose authors consented to make public are available online in the Submissions for Consultation Paper on Open Banking.

Throughout the course of its review, the Advisory Committee and Department of Finance engaged hundreds of stakeholders through public roundtables and bilaterally. A broad range of stakeholders were consulted as part of this process, from traditional financial sector stakeholders to Canadian consumers and civil society organizations representing small business owners, Canadians, and their families. Multi-stakeholder roundtables, which each engaged between 50 and 150 stakeholders, were held in Vancouver, Toronto, and Montreal. The Department of Finance and the Advisory Committee engaged international policy-makers to understand best practices in first-mover jurisdictions including Singapore, the United Kingdom, the European Union, and Australia. In support of the review, the Department of Finance also undertook qualitative public opinion research, the results of which can be found on the Library and Archives Canada website.

In January 2020, the Advisory Committee released a report entitled Consumer-directed finance: the future of financial services summarizing what it heard from stakeholders and learned from its examination of consumer-directed finance in other jurisdictions, formal recommendations, and considerations for next steps.

In 2020, the Advisory Committee undertook a second phase of consultation to identify implementation considerations, examining issues such as governance, consumer control of personal data, privacy, and security. This consultation included multiple workshops, each including between 24 and 48 industry stakeholders, such as banks, credit unions, fintechs, industry associations, consumer groups, provinces and territories, dealing with core issues, such as scope, governance, and accreditation. Canadians and stakeholders were again invited to share feedback, including through a dedicated email inbox, which resulted in 33 formal written submissions from industry stakeholders, including fintechs, banks and industry associations. A second round of quantitative and qualitative public opinion research was also undertaken. This second phase of consultation resulted in the Committee’s 2021 Final Report (PDF), which included 34 recommendations for a made-in-Canada approach to open banking, including to appoint an open banking Lead to develop the common rules, accreditation criteria, and to set technical standards.

Based on the Committee’s recommendation, Abraham Tachjian was appointed by the Minister of Tourism and Associate Minister of Finance in 2022 as the Open Banking Lead tasked with engaging industry, regulators, and consumer representatives. The Lead established four working groups on privacy, security, accreditation and liability, as well as a Steering Committee. This work resulted in more than 25 working group meetings and more than 200 stakeholder engagements between 2022 and 2023. Consumer groups were invited to participate and received funding to provide feedback to the Department of Finance on how to proceed with implementation using a consumer-first approach. The discussion guide and outcomes of each meeting are posted on the Department of Finance website and were used in the development of the Lead’s final recommendations to the Minister. Following the introduction of the first part of the Act in 2024, which included elements related to scope, governance and technical standards, the Department of Finance undertook five weeks of stakeholder consultation on the remaining elements, which culminated in a sworn-in review for industry, provinces (both departments and agencies), and consumer groups.

More than one hundred one-on-one discussions with stakeholders, including banks, credit unions, other federally and provincially regulated financial institutions, fintechs, and their industry associations, as well as consumer groups, and domestic and international subject matter experts, have also been ongoing throughout the regulatory development process. These one-on-one discussions have informed the government’s understanding of current industry practices, such as the API minimum service level requirements, and the impact of the regulatory requirements.

The Department of Finance has engaged extensively with provincial and territorial governments and regulatory bodies throughout the legislative and regulatory development process. For example, provincial governments and regulators were involved in the Open Banking Lead’s working groups. The Department of Finance has also met regularly with provincial and territorial governments and regulators, including bilateral discussions at the Deputy Minister level, and via existing multilateral fora. These engagements have helped inform the development of the proposed Regulations, particularly in areas where provinces oversee provincial financial institutions, including security, privacy (such as consumer consent and authentication), liability, complaints handling, and consumer protection.

The proposed Regulations were also developed in consultation with other federal government departments and agencies with roles and mandates relevant to the consumer-driven banking framework. This incudes the Bank of Canada as the supervisory authority responsible for implementing and overseeing the framework; OSFI as the supervisory authority responsible for the Bank Act; the Financial Consumer Agency of Canada as the supervisory authority responsible for the Bank Act’s Financial Consumer Protection Framework; Innovation, Science and Economic Development Canada (ISED) to ensure alignment with PIPEDA and any future successor legislation; the Competition Bureau as the independent law enforcement agency that protects and promotes competition law in Canada; and the Canadian Security Intelligence Service, the Communications Security Establishment, Public Safety Canada, and the Royal Canadian Mounted Police, on the inclusion and design of the framework’s national security safeguards. In 2024 senior executive and working-level committees were established to consult on the development of the remaining elements of the consumer-driven banking framework. This consultation ran in conjunction with industry and other stakeholder engagement and included the aforementioned departments and agencies.

The Department of Finance also consulted the Office of the Privacy Commissioner, an Office of Parliament, as an authority on privacy law and the protection of personal information.

Throughout this consultation process, concerns raised by individual stakeholders and industry groups varied by group. While views diverged in some places, there was general agreement that the framework should establish a process and criteria for regulation, and should establish common rules that protect consumers, while ensuring that all entities are equally subject to the same rules and requirements.

Incumbent financial institutions raised that forthcoming regulations should provide a secure foundation for consumer financial data sharing that apportioned liability appropriately (with respect to consent and authentication) and prohibited unsecure means of data sharing. They also noted that accreditation criteria for all prospective participating entities should be sufficiently robust to address operational and cybersecurity risks. Incumbent financial institutions also recommended that exceptions to the requirement to share data be defined broadly, to allow entities greater flexibility to stop sharing when a potential risk arises.

Feedback from incumbent financial institutions was considered in the development of the proposed Regulations. While the legislation clearly articulates the liability structure and respective responsibilities of participating entities, the proposed Regulations provide greater detail regarding these responsibilities to ensure there is no discrepancy about which party is responsible for which activity (e.g. consent and authentication). The proposed Regulations also adopt an approach to accreditation criteria that aims to address all of the public policy objectives of the framework, namely competition and innovation, security and stability and consumer protection, in a balanced manner. In so doing, the proposed Regulations ensure that risks are sufficiently addressed without creating unnecessary regulatory burden for new entrants.

The proposed Regulations do not broadly define the circumstances under which a participating entity is exempt from the requirement to share. Broad exemptions would be inconsistent with Canadians’ right to data portability, as enshrined in amendments to PIPEDA, which received Royal Assent in March 2026, and could lead to confusion or disputes about which circumstances applied. As a result, the proposed Regulations articulate circumstances (e.g. an account has been suspended) which align with those applied in open banking frameworks in other jurisdictions, adapted for the Canadian context. The included circumstances are based on extensive discussions with a broad cross-section of stakeholders including industry and regulators in other jurisdictions with open banking frameworks.

Credit unions and other provincially regulated financial institutions wanted to ensure that there were no barriers to provincial entities’ participation and to avoid duplication in regulatory burden associated with the accreditation process and the application of common rules. These proposed accreditation criteria for provincially regulated financial institutions address these concerns by relying on existing security protocols applied by a provincial regulator, and limiting accreditation criteria to areas not already addressed by a provincial regime, such as national security and technical standards. This approach ensures robust regulatory controls while seeking to minimize potential overlap or duplication of requirements for participating entities overseen by provincial regulators.

Fintechs and smaller entities wanted to ensure that the regulations did not stifle innovation or create substantial barriers to entry for new and smaller entities, that the regulatory burden was proportionate and scope was commensurate with existing data-sharing services. In response, the proposed Regulations related to the accreditation processes and criteria, as well as those related to participating entities’ responsibilities, reflect these concerns by striking a balance between the need for security and consumer protection and the need to be proportionate, risk-based and enable innovation and competition. They ensure that entities’ responsibilities at each part of the data sharing process are clearly articulated so that the liability to the consumer flows with the data and rests with the party at fault. The accreditation criteria proposed in the Regulations are reflective of feedback from federally and provincially regulated financial institutions that the path to entry should recognize and not duplicate existing requirements that address prudential and other forms of risk.

Provincial governments wanted to ensure that the framework, and related regulations in so far as they related to areas of shared responsibility, were not misaligned with provincial rules and that any overlap was minimized. These concerns were reflected in both the legislation and the proposed Regulations, which are limited to only the act of sharing the data and not the underlying financial products and services, which are overseen through existing federal and provincial rules.

In keeping with the Government’s commitment to robust consultation on the development of the Canadian consumer-driven banking framework, the proposed Regulations are subject to an extended prepublication period of 60 days to provide stakeholders with adequate time to provide meaningful feedback on the proposed Regulations. This extended period would provide the broad range of diverse stakeholders impacted by these novel requirements, including financial sector stakeholders, industry associations, provincial and territorial governments, and consumer groups, sufficient time to interpret and comment on the regulations. This will, in turn, ensure that the government can fully consider their unique perspectives in the finalization of the regulations and support efficient and timely implementation by all impacted stakeholders upon coming into force.

Indigenous engagement, consultation and modern treaty obligations

The proposed regulations are not expected to have any differential impacts on Indigenous peoples or implications for modern treaties, as per the Government of Canada’s obligations in relation to rights protected by section 35 of the Constitution Act, 1982, modern treaties, and international human rights obligations.

Instrument choice

The development of Canada’s consumer-driven banking framework has benefited from close observation of models employed in other jurisdictions. International approaches to consumer-driven banking vary between those that are industry-led and those that are government-led. Lessons learned from other jurisdictions demonstrate that government involvement in the establishment of common rules, technical standards, accreditation requirements, and oversight functions is critical to the success of the system, both in terms of creating a fair ecosystem for participants and ensuring consumer trust. To date, all successful consumer-driven baking frameworks have been government-led, with strong governance frameworks informed by legislation and regulation, such as those implemented in Australia, New Zealand, Brazil, India, the European Union, and the United Kingdom. Jurisdictions that have adopted purely industry-led models have largely abandoned these approaches, owing to fragmentation and poor consumer outcomes.

Domestic consultations and policy development have resulted in similar conclusions. Notably, Canada’s consumer-driven banking framework was informed by the work of the Open Banking Lead appointed in 2022, including recommendations that a Canadian framework be enshrined in legislation and supporting regulations. Building on the lessons learned from international experiences and domestic policy advice from subject matter experts, Canada has opted for a government-led model in which rules are set through legislation and regulation and authority to oversee the system is allocated to a government entity, in this case, the Bank of Canada. Enshrining the framework within legislation and regulation ensures that the system can meet key public policy objectives, including competition, innovation, utility to consumers, consumer protection and the ability to expand the framework to scope in other sectors in the future, all of which will maximize the benefits to the Canadian economy.

Regulatory analysis

Benefits and costs

The impacts of the proposed Regulations have been assessed in accordance with the Treasury Board of Canada Secretariat (TBS) Policy on Cost-Benefit Analysis and Canadian Cost-Benefit Analysis Guide. The benefits and costs associated with the proposed Regulations are determined by comparing the baseline scenario against the regulatory scenario. The baseline scenario depicts what is likely to happen in the future if the proposed Regulations are not implemented. The regulatory scenario describes the changes expected to occur due to the proposed Regulations. The impacts described are incremental differences between these two scenarios that are anticipated and thus attributable to the proposed Regulations.

The total cost of the proposed Regulations is $457.7 million over ten years in present value (TPV) [or $65.27 million annualized] in 2025 dollars. The TPV of benefits of the proposed Regulations is $13.2 billion over ten years (or $1.9 billion annualized) in 2025 dollars. Unless otherwise stated, all monetary values are expressed in 2025 dollars, discounted to 2027 using a discount rate of 7% over a 10-year period (2027 to 2036). There are additional qualitative benefits of the proposed Regulations, which are described below due to the difficulty associated with quantifying them.

A full cost-benefit report with more details on the methodology and assumptions employed is available upon request.

Baseline and regulatory scenarios

The baseline scenario assumes that the Consumer-Driven Banking Act has been implemented. As a result, the cost and benefit estimates presented in this analysis capture only the incremental impacts associated with the proposed Regulations relative to the legislative baseline. Costs and benefits that stakeholders would reasonably incur to comply with the Act itself are not included in this analysis.

Therefore, the costs described should be interpreted as the incremental administrative and compliance costs resulting from the proposed regulatory provisions, rather than the total costs of implementing the consumer-driven banking framework as a whole.

Benefits

A series of value-transfer scenarios based on United Kingdom open banking evidence presented in the report “Unlocking the Everyday: The Value, Growth and Opportunity of Open Banking in the UK (PDF)” were developed to estimate potential benefits in specific, well-defined use cases that could be enabled by the proposed Regulations. The United Kingdom was selected given its position as a global leader in open banking, and because it has consistently served as a benchmark for best practices and lessons learned for the development of the Canadian framework.

Across all use cases, it is assumed that the value transfer from the United Kingdom to Canada is appropriate after adjusting for inflation (1.045 from 2023 to 2025 and 1.021 from 2024 to 2025, where applicable) and the exchange rate (1.678 in 2023, 1.75 in 2024, and 1.842 in 2025, where applicable). All population-based calculations use the population aged 15 and over, with United Kingdom per-person benefit estimates applied to relevant Canadian populations (33.4 million in Canada and 57.5 million in the United Kingdom in 2024). Benefits are then estimated using a 27% participation rate, equivalent to approximately 9 million Canadians (27% of 33.4 million) adopting consumer-driven banking at the outset.

These use cases are illustrative and non-exhaustive and are intended to provide conservative estimates of benefits in areas where monetization is feasible. As the framework matures, a broader range of innovative use cases is expected to emerge, unlocking additional benefits not reflected in the present value estimates.

Enhanced affordability assessments for lending

For many people, credit is refused due to reliance on traditional credit scores that may not capture broader financial behaviour. Consumer-driven banking enabled tools can use financial transaction data to identify spending patterns and borrowing repayment habits that may prove that more people are a lower credit risk compared to information available in a typical credit report, helping more people gain access to credit, including at lower interest rates.

Nine million Canadians are credit unserved or underserved (TransUnion, 2022). The estimate assumes that the untapped credit demand, relative to this population, is comparable between the United Kingdom and Canada. The United Kingdom analysis assumes that incorporating transaction data from open banking into affordability assessments can expand lending by 14%. Therefore, a 14% increase in lending is applied to both the value of untapped credit demand and the credit unserved or underserved population to estimate the increase in credit extended and the number of individuals gaining access to credit. This results in a per-person benefit of $212.64, applied to 14% of the expected nine million users of consumer-driven banking who could gain access to credit.

Streamlined small and medium-sized enterprise (SME) account administration

Consumer-driven banking enabled tools can streamline administrative tasks for SMEs by allowing secure, real-time access to financial data across multiple accounts and financial institutions. Transaction categorization and cash flow tracking can reduce the need for manual data entry and simplify bookkeeping, tax preparation, and financial reporting processes. For SME owners, who often manage administrative functions alongside core business operations, these efficiencies translate into meaningful time savings that can be reallocated towards higher-value activities.

Time savings from using consumer-driven banking are assumed to be 52 hours per year from the United Kingdom study, valued at $35.60 per hour. SME participation is estimated by applying the same 27% participation rate used for consumer uptake of consumer-driven banking to the approximately 1.09 million Canadian SMEs, resulting in 293 731 SMEs that could benefit from reduced administrative burdens.

Optimization of savings accounts

Consumer-driven banking enabled tools can use chequing account transaction data to identify where money is going and how much is typically available each month for potential savings. With this information, the tool can provide advice and prompt consumers to direct their funds from a chequing account to a savings account with a higher return.

Higher returns on savings are estimated to generate a benefit of $57.78 per person annually. The estimate uses the assumption from the United Kingdom that 20% of the population holds account balances above a threshold and could shift funds into an easy-access savings account with a return of 2.11%, which is applied to the expected nine million users of consumer-driven banking. This could lead to more money invested in savings accounts and may result in overall lower interest rates for these types of accounts; however, this is not accounted for in these estimates.

Reducing the cost of recurring services

Many consumers fail to seek better deals at the end of a contract, often due to a lack of awareness or perceived complexity, which leads to consumers paying higher rates when competitive alternatives may exist. Consumer-driven banking enabled tools can address this issue by using transaction data to identify the cost of your services while scanning the market to identify opportunities for savings.

Mobile

The per-person annual savings from switching mobile plans is estimated at $119.65, based on the United Kingdom’s switching savings. The share of Canadians with a mobile phone, 95%, and the United Kingdom-derived assumption that 20% of consumers are on outdated plans imply that 19% of consumers would benefit (Media Technology Monitor, 2025). This proportion is applied to the expected nine million users of consumer-driven banking.

Broadband

Annual savings from switching broadband services are estimated at $187.56 per household, based on United Kingdom switching savings. This is converted to a per-person value of $78.15 using an average household size of 2.4 persons. The share of Canadians living in broadband-connected households, 96.4%, and the United Kingdom-derived proportion of households that are out of contract (43%) imply that approximately 41.5% of users would benefit, which is applied to the expected nine million users of consumer-driven banking (Canadian Radio-television and Telecommunications Commission, 2024).

Identification of unused subscriptions

The increase in subscription-based services has led to a growing number of consumers paying for services they no longer use or have forgotten to cancel, resulting in avoidable recurring expenses. Consumer-driven banking enabled tools can address this issue by aggregating a consumer’s financial transaction data across accounts to identify recurring subscription payments and flag potentially unneeded services.

The United Kingdom analysis uses reported estimates of the current total value of unused or forgotten subscriptions and assumes that, once consumer-driven banking tools identify all recurring subscription payments and allow users to flag those that are forgotten or unused, these subscriptions are cancelled, resulting in a 100% reduction in unused subscription spending. This estimate is converted into a per-person annual savings of $28.42 for consumer-driven banking users who have unused subscriptions. This is applied to the 66% of Canadians with forgotten subscriptions, within the 85% who pay for at least one subscription (Scotiabank, 2025; CRR Research, 2022), among the expected nine million consumer-driven banking users.

Costs

The direct costs associated with the proposed Regulations are expected to be borne by federally regulated financial institutions, provincially regulated financial institutions, payment service providers, other entities (fintechs, etc.), third-party service providers, mandated banks, the Bank of Canada, the external complaints body, and the technical standards body.

Some of the costs would occur as upfront, one-time costs in the first year of the framework, such as accreditation fees or capital costs related to building the information technology (IT) infrastructure. Other costs, such as labour costs related to quarterly or annual reports, are ongoing and would be incurred over the 10-year time horizon.

Accreditation and fees

It is estimated that businesses seeking entry into the framework would incur administrative and compliance costs related to accreditation and ongoing supervisory oversight. In addition to labour costs, applicants would incur a one-time accreditation fee per application of $2,500 adjusted to inflation and rounded to the nearest $100 on a yearly basis.

Participating entities, ATPSPs, and the external complaints body would also incur ongoing annual assessment fees. The external complaints body would be subject to a fixed annual fee of $50,000, and ATPSPs subject to a fixed annual fee of $10,000. For participating entities, the annual assessment fee is composed of a base fee and a variable fee. The base fee payable by participating entities is determined according to the asset tier corresponding to the entity’s total asset value, ranging from $10,000 up to $150,000. The variable fee is calculated by applying the applicable Variable Fee Distribution percentage to the pool of remaining recoverable costs that have been applied, distributed equally between entities within that tier. The percentage assigned to each asset tier determines the proportion of the remaining recoverable costs to be allocated equally between entities within that tier. However, any estimate of the value of remaining recoverable costs before the framework is in operation would be highly speculative at this time, so this variable fee has not been included in the analysis.

Routine reporting, notices, signage, and record keeping

It is estimated that regulated entities would incur recurring administrative costs associated with routine reporting, notices, signage updates, and record-keeping obligations. Certain notice-of-change obligations are estimated to require 30 minutes per filing, while annual reporting obligations are estimated to require three hours per report. Minor disclosure-related obligations, such as updating required signage where applicable, are estimated to require one hour annually per participating entity. Record-keeping obligations may also require one-time IT build costs of approximately $5,000 for some participating entities and ATPSPs, in addition to ongoing labour to maintain records. No material incremental record-keeping cost is assumed for mandated banks, federally regulated financial institutions, and provincially regulated financial institutions where comparable systems and processes are already expected to exist.

Operational requirements

Participating entities would be subject to operational requirements and would likely incur both upfront capital costs and ongoing compliance labour costs related to authentication, verification, authorization, minimum service-level standards, and right of refusal. Upfront capital costs are associated with establishing or adapting technical functionality, including API capabilities, where required. These one-time costs are estimated at $10,000 for mandated banks, federally regulated financial institutions, and provincially regulated financial institutions, and $5,000 for PSPs and other entities where implementation is expected to be less complex.

Ongoing labour costs would also be incurred to support authentication, verification, authorization, minimum service-level requirements, and the administration of refusal decisions in prescribed circumstances. These ongoing costs are estimated at approximately three months equivalent annually for mandated banks and financial institutions, and one month annually for PSPs and other entities reflecting their lower expected implementation complexity.

Security compliance and incident reporting

It is estimated that participating entities would incur upfront and ongoing compliance costs to establish and maintain security safeguards, as well as additional costs when reportable incidents occur. For PSPs, it is assumed that 75% already maintain sufficient security infrastructure, such that only 25% would incur upfront implementation costs. For these entities, and for other entities that do not already have sufficient measures in place, upfront implementation costs are estimated at one quarter of a full-time equivalent. Ongoing compliance with security requirements is estimated to require approximately one week of labour annually for affected entities. Where a reportable incident occurs, additional labour would be required to investigate the incident and complete reporting obligations. The cost of incident investigation and reporting is estimated at 100 hours per incident. In the central analysis, such incidents are assumed to affect 2% of entities per year.

Bank of Canada registry

It is estimated that the Bank of Canada would incur upfront and ongoing costs to establish and maintain core implementation infrastructure to support the operation of the framework. This includes a one-time capital cost to build an IT system linked to a public registry in order to facilitate real-time registry updates to participating entities. In addition, ongoing labour is required to maintain and update the registry and supporting IT infrastructure.

Clarificatory provisions and qualitative consumer impacts

For some provisions, no material incremental quantitative cost is estimated because the proposed Regulations would not incur a cost, as they are intended to clarify an existing underlying obligation from the Act. In these cases, the proposed Regulations provide additional specificity, but are not expected to generate a distinct incremental labour or capital cost.

Cost-benefit statement
Table 1: Monetized benefits
Impacted stakeholder Description of benefit First year Final year Total (PV) Annualized value
Canadians Enhanced affordability assessments for lending $273,282,386 $326,597,748 $2,078,722,737 $295,963,352
Canadians/SMEs Streamlined SME account administration $701,003,160 $837,763,667 $5,332,181,230 $759,182,648
Canadians Optimization of savings accounts $106,090,579 $126,788,063 $806,978,097 $114,895,526
Reducing the cost of recurring services $502,840,409 $600,940,836 $3,824,856,066 $544,573,455
Identification of unused subscriptions $146,367,195 $174,922,347 $1,113,342,216 $158,514,884
All stakeholders Total benefits $1,729,583,729 $2,067,012,661 $13,156,080,347 $1,873,129,866
Table 2: Monetized cost
Impacted stakeholder Description of cost Base year Final year Total (PV) Annualized value
Government, agencies, and Crown corporations Costs incurred by Bank of Canada $1,110,576 $54,103 $1,436,472 $204,521
Industry Costs incurred by FRFIs, PRFIs, mandated banks, other entities, and third-party service providers $47,972,765 $72,678,784 $455,867,781 $64,905,316
Framework bodies Costs incurred by the external complaints body and the technical standards body $52,172 $52,172 $366,434 $52,172
All stakeholders Total costs $49,135,513 $72,785,059 $457,670,687 $65,162,010
Table 3: Summary of monetized costs and benefits (in millions of dollars)
Impacts Base year Final year Total (PV) Annualized value
Total benefits $1,729,583,729 $2,067,012,661 $13,156,080,347 $1,873,129,866
Total costs $49,135,513 $72,785,059 $457,670,687 $65,162,010
NET IMPACT $1,680,448,216 $1,994,227,602 $12,698,409,660 $1,807,967,856
Quantified (non-monetized) and qualitative impacts
Positive impacts
Negative impacts

Sensitivity analysis and distributional analysis summary

The impacts of the proposed Regulations are expected to fall primarily on institutional and business participants rather than on consumers. Direct compliance and administrative costs would be concentrated among entities that are mandated to participate in, opt into, oversee, or support the framework, including costs related to implementation, labour, accreditation, reporting, record keeping, security compliance, service standards, and incident response. These impacts are expected to be proportionately greater for small businesses, since many compliance costs are fixed and therefore represent a larger burden relative to firm size and resources. Based on current estimates, approximately 578 of the 680 affected businesses are small businesses, and the average small business is expected to incur an annualized cost of $89,133. Although large institutions, including mandated banks, may face higher absolute costs because of their scale and system complexity, they are generally better positioned to absorb these costs. No distinct differential impacts have been identified for Indigenous groups, demographic subgroups, or regions. Consumers are not expected to face direct costs, consistent with the Act’s prohibition on charging for data sharing, although limited indirect costs could arise if some business costs are passed on through the pricing of financial services.

Sensitivity analysis indicates that the main cost drivers are the number of participating entities accredited in the first year and the discount rate used in the cost-benefit analysis. The central scenario assumes a 25% first-year opt-in rate, equivalent to approximately 680 affected businesses, while the low and high scenarios assume opt-in rates of 15% and 35%, respectively. Under these scenarios, TPV costs range from $425.9 million to $486.3 million, and annualized costs range from $60.6 million to $69.2 million. While total costs increase as more entities participate, the average annualized cost per entity declines as fixed costs are spread across a larger number of participants. The analysis assumes opt-in rates rise by 15 percentage points annually until reaching a steady-state cap of 80%. Sensitivity testing on the discount rate shows that TPV costs range from $532.2 million at 4% to $397.7 million at 10%, compared with $457.7 million under the central 7% rate.

Small business lens

Analysis under the small business lens concluded that the proposed Regulations would impact small businesses. It is estimated that approximately 680 businesses would be impacted by these proposed Regulations, with 86% being small businesses, resulting in a total of 578 small businesses impacted.

It is expected that participating entities or ATPSPs that are small businesses would incur administrative and compliance costs. These costs stem from the provision of documents to the Bank of Canada under various regulatory requirements, costs to implement and demonstrate compliance with the technical standard and security measures, as well as additional human resource costs and IT system changes that would be required to support the implementation of these regulatory provisions.

Alternative compliance options for small businesses would not be possible because the proposed Regulations are intended to create the same privacy, liability, and security safeguards for all consumers consenting to their data being shared across the framework, regardless of the size of the participating entity or ATPSP involved in the data sharing process.

However, under the proposed Regulations, the Bank of Canada would establish a tiered assessment fee structure for participating entities based on the value of their total assets, such that smaller businesses would pay lower annual assessment fees than larger entities.

Small business lens summary
Table 4: Costs
Administrative or compliance Description of cost Present value Annualized value
Administrative Total administrative costs incurred by small businesses $2,695,743 $383,813
Compliance Total compliance costs incurred by small businesses $359,261,686 $51,150,782
Total Total costs $377,714,728 $53,778,080
Table 5: Net impacts
Amount Present value Annualized value

Net impact on all impacted small businesses
[Total benefits minus total costs]

$361,957,429 $51,534,595

Average net impact on each impacted small business
[Net impact divided by number of impacted small businesses]

$626,036 $89,133

One-for-one rule

The proposed Regulations are a new regulatory title that introduces new administrative costs to businesses.

Entities that are mandated or opt-in to participate in the consumer-driven banking framework will experience new administrative costs associated with the proposed Regulations. This burden stems from new reporting and information requirements, as well as human resources and IT system costs to support the implementation of the proposed Regulations.

Using assumptions and data presented above and the methodology developed in the Red Tape Reduction Regulations, which requires results to be reported in 2012 CAD and discounted to a 2012 base year, it is estimated that the regulated community will assume total administrative costs of $849,651 (present value) over 10 years, or $120,971 annualized for all participating entities and ATPSPs. This equates to $1,249 (present value) per business over 10 years or $178 annualized per business.

Regulatory cooperation and alignment

Worldwide, the development of open banking frameworks has been uneven, shaped by diverse regulatory models, technical standards, and institutional priorities. The Department of Finance has examined open banking systems in other jurisdictions, learning from their implementation experiences, to help develop a made-in-Canada consumer-driven banking framework. The United Kingdom and Australia are two key jurisdictions where the Department of Finance is attentive to lessons learned due to comparable regimes and demonstrated success, while also monitoring developments in other jurisdictions, like Brazil, the United States, and countries belonging to the European Union. Key elements of the proposed Regulations, such as the accreditation and reporting requirements, align with many of the requirements found in successful open banking regimes, such as the framework implemented in Australia.

Domestically, the Act accounts for provincial and territorial regulatory cooperation and alignment by enabling the Minister of Finance to designate a provincial or territorial authority to supervise certain provisions on an identified provincial financial institution or class of provincial financial institutions when certain provisions are met. This will facilitate oversight of provincial entities while respecting their jurisdiction. The Act also authorizes the Minister of Finance to issue an order that exempts a participating entity or class of participating entities from the legislative obligation to be a member of the federally designated external complaints body if they are a member of a provincial equivalent, for example, a provincially designated or regulated complaints dispute body. The Act further establishes a federal, provincial and territorial advisory committee that is co-chaired by the federal government and one rotating provincial co-chair. This committee will serve as the forum to discuss future legislative and regulatory developments, operational challenges, and priorities for the consumer-driven banking framework.

All participating entities will be subject to the consumer-driven banking framework and Bank of Canada supervision, unless otherwise provided, as described above. To facilitate the participation of provincially regulated financial institutions, the governance model is structured in a manner that allows provincial credit unions and crown corporations that offer deposit-taking services or provincial insurance companies to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.

International obligations

The proposal is not linked to any international agreements or obligations.

Effects on the environment

In accordance with the Cabinet Directive on the Environmental Assessment of Policy, Plan and Program Proposals, a preliminary scan concluded that this proposal is not expected to result in any direct and significant environmental impacts, including Canada’s emission targets. Therefore, a strategic environmental assessment is not required.

Gender-based analysis plus

A gender-based analysis plus (GBA+) assessment was undertaken for the proposed Regulations. Overall, the proposed Regulations are expected to enable data sharing to support consumers and small businesses in exercising a data portability right in a safe and secure ecosystem. Canadians would have the option of secure access to innovative financial services and products that better meet their needs, the ability to provide specific and revokable consent, improved consumer protections and reduced exposure to liability, privacy, and security risks.

There are sources that suggest vulnerable consumers, such as those with lower income, may benefit from real-time access to their whole financial picture (American Banker). Similarly, consumers with limited credit profiles such as new and younger Canadians may benefit from the ability to use their transaction history to build credit. Services that, for example, enable renters to use evidence of on-time rental payments to demonstrate credit worthiness may facilitate access to home ownership and reduced borrowing costs. Younger generations may also be more likely to make use of digital financial services and therefore reap greater benefits from consumer-driven banking.

It is unclear that differences along age and income lines will produce benefits that are predominately stronger than the rest of the population at large. Given that all Canadians are expected to benefit from the proposed Regulations, no specific measures to address or mitigate GBA+ impacts are required.

Implementation, compliance and enforcement, and service standards

Implementation

The proposed Regulations would come into force when the relevant provisions of the Act come into force, as fixed by orders of the Governor in Council. The proposed Regulations would come into force following a staggered approach, starting with the accreditation requirements, with the requirements related to common rules and assessment fees following at later dates.

Elements of the framework related to “in scope data” (e.g. accounts) would also be phased in with staggered coming-into-force dates in accordance with the complexity of account type, beginning with deposit and payment accounts, then moving to lending accounts, registered accounts, and then non-registered accounts.

While the final decision on the precise timing of the staggered coming-into-force dates would be taken following the Canada Gazette, Part I, consultations, the full suite of proposed Regulations is intended to be in force within one year of final publication in the Canada Gazette, Part II.

Ministerial Orders to designate the technical standards body and external complaints body would be issued and published in the Canada Gazette in advance of the coming into force of the proposed Regulations to fully operationalize the framework.

Authorities for the Minister to designate a provincial or territorial authority to supervise certain legislative provisions are not mandatory for the framework to come into force or to be implemented. The provision is an enabling authority that provinces can request be exercised.

The Bank of Canada is a Crown corporation that operates independently and at arm’s length from the federal government. Once the proposed Regulations are published in the Canada Gazette, Part II, the Bank of Canada will issue guidelines for consultation on specific topics related to the Act to further clarify its supervisory expectations. These documents will be published on the Bank of Canada website in advance of the proposed Regulations coming into force and will explain how the Bank of Canada interprets the Act and provide transparency around the Bank of Canada’s supervisory role.

Compliance and enforcement

Under the Act and proposed Regulations, the Bank of Canada will be responsible for supervising participating entities and ATPSPs, promoting compliance among participating entities of their obligations under the Act and proposed Regulations, and monitoring and evaluating trends related to Canada’s consumer-driven banking framework.

All participating entities will be subject to the consumer-driven banking framework and Bank of Canada supervision. To facilitate the participation of provincially regulated financial institutions, the governance model will be structured to allow provincial credit unions and crown corporations that offer deposit-taking services and provincial insurance companies to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.

In addition, the Act authorizes the Minister of Finance, upon request from a provincial equivalent, to designate the supervision of certain legislative provisions to a provincial authority when certain criteria are met. The provincial authority will be responsible for the supervision of the Act’s obligations, but the enforcement of those provisions will rest with the Bank of Canada. It is anticipated that clear information sharing agreements will be in place prior to any such designation to ensure that effective collaboration can occur between the federal and provincial supervisors. The collaborative nature of the framework is further enhanced by the establishment of a federal, provincial and territorial advisory committee, which will provide advice to all relevant federal and provincial ministers regarding the implementation and evolution of the framework.

The Act also provides the Minister of Finance with the authority to address risks related to national security that could be posed by participating entities and ATPSPs. This includes the ability to refuse the accreditation of entities and third-party service providers seeking to enter the consumer-driven banking framework, revoking accreditation status, ordering undertakings or conditions, as well as issuing national security orders for a participating entity to take or refrain from any action. The Minister will be supported by the Department of Finance, as well as Canada’s security and intelligence community (government authorities) providing information (intelligence and analysis) in accordance with their respective mandates.

The legislation provides the Bank of Canada with a range of enforcement tools, such as the ability to suspend or revoke accreditation, issue undertakings, terms or conditions, or impose administrative monetary penalties on entities that violate the Act.

Service standards

To ensure clarity and consistency across all framework participants, the timelines for accreditation and national security reviews are set out in the proposed Regulations. Further information on these timelines can be found in the “Description” section of this Regulatory Impact Analysis Statement.

Contact

KĂŻrsten Fraser
Director, Financial Services Innovation
Financial Services Division
Financial Sector Policy Branch
Department of Finance Canada
90 Elgin Street
Ottawa, Ontario
K1A 0G5
Email: obbo@fin.gc.ca

PROPOSED REGULATORY TEXT

Notice is given that the Governor in Council proposes to make the annexed Consumer-Driven Banking Regulations under sections 155 and 178 of the Consumer-Driven Banking Act footnote a.

Interested persons may make representations concerning the proposed Regulations within 60 days after the date of publication of this notice. They are strongly encouraged to use the online commenting feature that is available on the Canada Gazette website. However, if they use email, mail or any other means, the representations should cite the Canada Gazette, Part I, and the date of publication of this notice, and be sent to KĂŻrsten Fraser, Director, Financial Services Division, Financial Sector Policy Branch, Department of Finance Canada, 90 Elgin Street, Ottawa, Ontario K1A 0G5 (email: obbo@fin.gc.ca).

Please note that as part of the publication process, all representations, including attachments, will be published on the Canada Gazette website, subject to its terms of use relating to the provision of comments.

Ottawa, June 19, 2026

Janna Rinaldi
Assistant Clerk of the Privy Council

Consumer-Driven Banking Regulations

Definition

Definition of Act

1 In these Regulations, Act means the Consumer-Driven Banking Act.

Application

Data

2 For the purpose of subsection 10(1) of the Act, the data in respect of which the Act applies includes the following data relating to the products and services referred to in that subsection:

Accreditation

Accreditation as a Participating Entity

Application — federal or provincial financial institution

3 (1) An application referred to in subsection 15(1) of the Act must contain

System

(2) The application must be made using the electronic system provided by the Bank for that purpose.

Application — registered payment service provider

4 (1) An application referred to in subsection 17(1) of the Act must contain

System

(2) The application must be made using the electronic system provided by the Bank for that purpose.

Requirements — registered payment service provider

5 (1) For the purpose of subsection 17(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:

Continuation of requirements

(2) A participating entity that is accredited under subsection 17(1) of the Act must continue to be a registered payment service provider and meet the requirements set out in paragraphs (1)(a), (d) and (e).

Application — other entity

6 (1) An application referred to in subsection 19(1) of the Act must contain

System

(2) The application must be made using the electronic system provided by the Bank for that purpose.

Requirements — other entity

7 (1) For the purpose of subsection 19(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:

Continuation of requirements

(2) A participating entity that is accredited under subsection 19(1) of the Act must continue to meet the requirements set out in paragraphs (1)(a), (d) and (e).

Accreditation fee

8 (1) For the purposes of subsections 15(2), 17(2) and 19(2) of the Act, the accreditation fee is to be determined by the following formula and rounded to the nearest multiple of $100 or, if the result obtained is equidistant from two multiples of $100, to the higher of them:

$2,500 Ă— (A Ă· B)
where
A
is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year immediately before the year in which the application is made; and
B
is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year in which this section comes into force.

Exception

(2) Despite subsection (1), the fee to be included with an application for accreditation that is made in the calendar year in which this section comes into force is $2,500.

No decrease

(3) Despite subsection (1), if a fee determined under that subsection is less than the fee that was required to be included with an application made in the previous calendar year, the fee is instead equal to the fee applicable in that previous year.

Review of refusal to accredit

9 (1) For the purpose of subsection 21(1) of the Act, the period within which an applicant may make a request to the Governor for a review of the decision to refuse its application for accreditation is 30 days beginning on the day after the day on which the applicant is notified of that decision.

Decision of Governor

(2) For the purpose of subsection 21(2) of the Act, the period within which the Governor must accredit the applicant or confirm the refusal to accredit is 120 days beginning on the day after the day on which the Governor gives the applicant an opportunity to make representations.

Request for revocation

10 The other information that a participating entity must provide to consumers under paragraph 22(1)(b) of the Act is the following:

Notice of intent to revoke accreditation

11 (1) For the purpose of subsection 26(1) of the Act, the period within which a participating entity may make a request to the Governor for a review of a notice of intent to revoke its accreditation is 30 days beginning on the day after the day on which it is given the notice of intent.

Decision of Governor

(2) For the purpose of subsection 26(2) of the Act, the period within which the Governor must revoke the participating entity’s accreditation or withdraw the notice of intent is 60 days beginning on the day after the day on which the Governor gives the participating entity an opportunity to make representations.

Former participating entity

12 The other information that a former participating entity must provide to consumers under section 29 of the Act is the following:

Accreditation as a Third-Party Service Provider

Application

13 (1) An application referred to in subsection 32(1) of the Act must contain

System

(2) The application must be made using the electronic system provided by the Bank for that purpose.

Requirements

14 (1) For the purpose of subsection 32(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:

Continuation of requirements

(2) An accredited third-party service provider must continue to meet the requirements referred to in subsection (1).

Accreditation fee

15 (1) For the purpose of subsection 32(2) of the Act, the accreditation fee is to be determined by the following formula and rounded to the nearest multiple of $100 or, if the result obtained is equidistant from two multiples of $100, to the higher of them:

$2,500 Ă— (A Ă· B)
where
A
is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year immediately before the year in which the application is made; and
B
is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year in which this section comes into force.

Exception

(2) Despite subsection (1), the fee to be included with an application for accreditation that is made in the calendar year in which this section comes into force is $2,500.

No decrease

(3) Despite subsection (1), if a fee determined under that subsection is less than the fee that was required to be included with an application made in the previous calendar year, the fee is instead equal to the fee applicable in that previous year.

Review of refusal to accredit

16 (1) For the purpose of subsections 34(1) of the Act, the period within which an applicant may make a request to the Governor for a review of the decision to refuse its application for accreditation is 30 days beginning on the day after the day on which the applicant is notified of that decision.

Decision of Governor

(2) For the purpose of subsection 34(2) of the Act, the period within which the Governor must accredit the applicant or confirm the refusal to accredit is 120 days beginning on the day after the day on which the Governor gives the applicant an opportunity to make representations.

Notice of intent to revoke accreditation

17 (1) For the purpose of subsection 39(1) of the Act, the period within which an accredited third-party service provider may make a request to the Governor for a review of a notice of intent to revoke its accreditation is 30 days beginning on the day after the day on which it is given the notice of intent.

Decision of Governor

(2) For the purpose of subsection 39(2) of the Act, the period within which the Governor must revoke the third-party service provider’s accreditation or withdraw the notice of intent is 60 days beginning on the day after the day on which the Governor gives the third-party service provider an opportunity to make representations.

Former accredited third-party service provider

18 The other information that a former accredited third-party service provider must provide to participating entities under section 42 of the Act is the following:

Appeal to Federal Court

Period

19 For the purpose of subsection 43(1) of the Act, the period within which an applicant may appeal to the Federal Court a decision referred to in subsection 21(3) of the Act, a participating entity may appeal to the Federal Court a decision referred to in subsection 26(3) of the Act or an accredited third-party service provider may appeal to the Federal Court a decision referred to in subsection 34(3) or 39(3) of the Act is 30 days beginning on the day after the day on which the applicant, the participating entity or the accredited third-party service provider, as the case may be, is notified of the decision.

Registry

Name and address

20 For the purposes of paragraphs 44(a) and (f) of the Act, the names and addresses that must be included in the registry are the legal and any trade names of each participating entity and accredited third-party service provider and their primary civic and mailing addresses.

Other information

21 For the purposes of paragraphs 44(e) and (h) of the Act, the other information that must be included in the registry is the following:

Updating

22 The registry must be updated immediately after any of the information referred to in section 44 of the Act changes or, in the case of information of which the Bank must be notified, immediately after the Bank is notified of the change or the change takes effect, whichever is later.

National Security

Interpretation

Affiliation, subsidiaries and control

23 For the purposes of this section and section 25,

Definition of senior officer

24 In paragraph 25(g), senior officer means

Application for Accreditation

Information to be provided in application

25 The following information is to be provided for the purposes of paragraphs 3(1)(n), 4(1)(s), 6(1)(u) and 13(1)(q):

Decision to review

26 (1) For the purpose of subsection 47(1) of the Act, the period within which the Minister may decide to review an application for accreditation is 60 days beginning on the day after the day on which the Minister is provided with a copy of the application.

Extension of period

(2) For the purpose of subsection 47(2) of the Act, each period for which the period referred to in subsection (1) may be extended is 60 days.

Review

27 (1) For the purpose of subsection 48(1) of the Act, the period within which the Minister must conduct a review of an application for accreditation is 180 days beginning on the day after the day on which Minister decides to review the application.

Extension of period

(2) For the purpose of subsection 48(2) of the Act, each period for which the period referred to in subsection (1) may be extended is 180 days.

Review of directive

28 For the purpose of subsection 53(1) of the Act, the period within which an applicant may request a review by the Minister of a directive to the Bank to refuse accreditation is 30 days beginning on the day after the day on which the Bank notifies the applicant that their application for accreditation has been refused.

Additional information

29 For the purpose of subsection 54(2) of the Act, the period within which an applicant must provide the requested information to the Bank is 30 days beginning on the day after the day on which the applicant receives the request.

Suspension and Revocation

Review of notice of intent

30 For the purpose of subsection 67(1) of the Act, the period within which a participating entity or accredited third-party service provider may request a review by the Minister of a notice of the Minister’s intent to issue a directive to the Bank to revoke the participating entity’s or accredited third-party service provider’s accreditation is 30 days beginning on the day after the day on which the Bank notifies the participating entity or accredited third-party service provider of the notice of intent.

Former participating entity

31 The other information that a former participating entity must provide to consumers under subsection 69(4) of the Act is the following:

Former accredited third-party service provider

32 The other information that a third-party service provider whose accreditation has been revoked must provide to participating entities under subsection 69(5) of the Act is the following:

Additional information

33 For the purpose of subsection 71(2) of the Act, the period within which a participating entity or accredited third-party service provider must provide the requested information to the Bank is 15 days beginning on the day after the day on which the participating entity or accredited third-party service provider receives the request.

Duties of Participating Entities

Data Sharing

Verification

34 A participating entity must not share a consumer’s data under subsection 76(1) of the Act unless

Exceptions to duty to share

35 (1) A participating entity is not required under subsection 76(1) of the Act to share a consumer’s data with another participating entity if

Data older than 24 months

(2) Subsection 76(1) of the Act does not apply in relation to

Notice to Bank

(3) For greater certainty, a participating entity’s obligation under subsection 76(4) of the Act to notify the Bank that it is not sharing a consumer’s data as required by subsection 76(1) of the Act applies to situations where the reason for not sharing is that one of the circumstances referred to in subsection (1) of this section exists or the consumer’s consent has not yet been renewed following a circumstance referred to in subsection 44(1) or section 46.

Notice to other participating entity

(4) A participating entity that does not share a consumer’s data because of one of the circumstances referred to in subsection (1) or because the consumer’s consent has not yet been renewed following a circumstance referred to in subsection 44(1) must notify the other participating entity of the reason for not sharing the data.

Requirements

36 (1) A participating entity that shares a consumer’s data under subsection 76(1) of the Act must

Planned outages

(2) For the purpose of paragraph (1)(b), planned outages are outages of which the Bank is notified at least one week in advance — or, if they are necessary to resolve a critical service or security issue, as soon as feasible — and whose duration and frequency are commensurate to outages of the participating entity’s consumer-facing electronic systems.

Security

Security safeguards

37 (1) For the purpose of section 79 of the Act, the security safeguards are the following:

Proportionality

(2) The implementation of the security safeguards must be proportionate to the sensitivity of the data and the participating entity may segment its network into various security zones to ensure an adequate level of protection for all data.

Federal or provincial financial institution

(3) A federal financial institution or a provincial financial institution is presumed to have implemented the security safeguards unless the Superintendent of Financial Institutions or the appropriate provincial authority that regulates or supervises the provincial financial institution has identified deficiencies in that entity’s ability to protect itself against threats to the integrity and security of its data and has directed it to take remedial measures.

Designation of responsible officer or employee

38 A participating entity must, without delay after designating an officer or employee under section 80 of the Act, provide the Bank with that individual’s name, title, brief job description, telephone number and email address.

Report of breach to Bank

39 A report under subsection 82(1) of the Act must contain

Notice to consumer of breach

40 (1) A notice given under subsection 82(3) of the Act must contain

Manner

(2) For the purpose of subsection 82(5) of the Act and subject to subsection (3), the notice must be given directly to the consumer in person, by telephone, by mail, by email or using any other form of communication that a reasonable person would consider appropriate in the circumstances.

Exception — indirect notice

(3) If the participating entity does not have any contact information for the affected consumer that would allow them to give notice in accordance with subsection (2), or if giving notice in that manner would be likely to cause further harm to the affected consumer or undue hardship for the participating entity, the participating entity must give the notice by public communication or similar means that could reasonably be expected to reach the affected consumer.

Investigation of breach

41 The conclusions that are reported to the Bank under section 83 of the Act must address the following subjects and must be reported as soon as feasible using the electronic system provided by the Bank for that purpose:

Consent

Use of data

42 Despite subsection 85(6) of the Act, a participating entity may use a consumer’s data that it receives from another participating entity for a use other than those described in the information provided to the consumer under paragraph 85(4)(b) of the Act if

Record of consent

43 (1) Each record of express consent that is kept by a participating entity under subsection 85(8) of the Act must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept in a format that is — or can readily be made — intelligible to the Bank until the day that is five years after the day on which the consent ceases to be valid.

Protective measures

(2) The participating entity must take reasonable measures with respect to the record to

Renewal of consent

44 (1) For the purpose of subsection 87(1) of the Act, the circumstances in which a participating entity must renew a consumer’s express consent are the following:

Initiation

(2) The participating entity must initiate the renewal process as soon as feasible after it becomes aware of a circumstance referred to in subsection (1).

Deletion of data

45 (1) For greater certainty, a participating entity is not required, under subsections 87(5) and 90(4) of the Act, to delete data that has been irreversibly and permanently modified to ensure that there is no reasonably foreseeable risk in the circumstances that the consumer can be identified from it, whether directly or indirectly, by any means.

Notice to consumer

(2) A participating entity that does not delete certain data whose deletion is requested by a consumer because the deletion is prohibited by law or is not required under subsection (1) must notify the consumer as soon as feasible, in writing, of the reasons for not deleting the data. If the deletion is prohibited by law but that situation is expected to be temporary, the notice must also indicate when the participating entity will be able to delete the data and must confirm that the deletion will be completed without further action by the consumer.

Request for renewal

46 For the purpose of section 93 of the Act, a request by a participating entity to another participating entity that the latter renew a consumer’s express consent must be made as soon as feasible after

Consumer Authentication

Requirements

47 (1) To enable a participating entity that provides a consumer’s data to comply with its duties under subsection 92(1) of the Act, a participating entity that requests a consumer’s data for the first time during any period for which the consumer’s consent has been obtained or renewed must, with the knowledge of the consumer, redirect the consumer to the participating entity from which the data is requested for confirmation of the consumer’s authentication information and must advise the participating entity from which the data is requested of the duration and scope of the consumer’s consent.

Participating entity that provides data

(2) A participating entity that receives a request to provide a consumer’s data must, if and only if it is the first such request received by the participating entity during a period for which the consumer’s consent has been obtained or renewed and regardless of the manner in which the consumer accesses the participating entity’s products or services,

Consumer Measures

Display of sign

48 (1) The sign that is displayed by a participating entity for the purpose of paragraph 94(a) of the Act must be clearly visible during business hours from the main customer area of the location in question.

False impression

(2) The location and manner in which a sign is displayed under section 94 of the Act must not give the impression that an individual or entity is a participating entity, or that data relating to a particular product or service is subject to the consumer-driven banking framework, if that is not the case.

Provision of Information

Notice of change

49 (1) For the purpose of subsection 98(1) of the Act, the changes of which the participating entity must notify the Bank are changes to

Timing

(2) For the purpose of subsection 98(2) of the Act, the period within which the notice must be given is

Annual report

50 (1) The information that must be included in the report that a participating entity submits to the Bank under section 100 of the Act is the following:

Definition of reporting year

(2) In this section, reporting year means the participating entity’s financial year in respect of which the report is submitted to the Bank.

Record Keeping

Duty to keep records

51 (1) The records that a participating entity must keep under section 102 of the Act are those sufficient to demonstrate its compliance with the Act and these Regulations.

Period of retention

(2) The records must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept until the day that is five years after the day on which the records cease to demonstrate the participating entity’s current compliance with the Act and these Regulations.

Form

(3) The records must be kept, in electronic form, in a format that is — or can readily be made — intelligible to the Bank.

Protective measures

(4) The participating entity must take reasonable measures with respect to the records to

Liability

Safeguarding of authentication information

52 Every participating entity

Liability of participating entities

53 For greater certainty, if, under subsection 103(1) of the Act, a consumer is not liable for a financial loss arising from the loss of, unauthorized access to or unauthorized use of their data that occurs in relation to the sharing of data in accordance with the Act, liability as between the participating entities involved in the sharing of that data is, for the purpose of section 104 of the Act, to be determined as follows:

Duties of Accredited Third-Party Service Providers

Provision of Information

Notice of change

54 (1) For the purpose of subsection 120(1) of the Act, the changes of which the accredited third-party service provider must notify the Bank are changes to

Timing

(2) For the purpose of subsection 120(2) of the Act, the period within which the notice must be given is

Record Keeping

Duty to keep records

55 (1) The records that an accredited third-party service provider must keep under section 122 of the Act are the following:

Period of retention

(2) The records must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept until the day that is five years after the day on which

Form

(3) The records must be kept, in electronic form, in a format that is — or can readily be made — intelligible to the Bank.

Protective measures

(4) The accredited third-party service provider must take reasonable measures with respect to the records to

Technical Standards Body

Annual report

56 (1) For the purpose of section 128 of the Act, the annual report that must be submitted to the Bank by the technical standards body must include the following information in relation to the year in respect of which the report is submitted:

Time and manner

(2) The report must be submitted using the electronic system provided by the Bank for that purpose within seven days following each anniversary of the day on which the Minister’s order designating the body as the technical standards body comes into force.

Evidentiary Privilege

Supervisory information

57 For the purpose of subsection 133(1) of the Act, the information that must not be used as evidence in any civil proceedings and that is privileged for that purpose is the following:

Use of information

58 (1) For the purpose of subsection 133(3) of the Act, the Minister, the Governor, the Bank and the Attorney General of Canada may use the information referred to in section 57 of these Regulations as evidence in any proceeding.

Certain Acts

(2) For the purpose of subsection 133(4) of the Act, a participating entity or accredited third-party service provider may use the information referred to in section 57 of these Regulations as evidence in any proceeding referred to in that subsection.

Assessment of Fees

Participating entities

59 (1) For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed, in respect of a calendar year, against an individual or entity that was a participating entity at any time during that calendar year is to be determined by the formula

A + B − C
where
A
is the base assessment amount determined under subsection (2) for the participating entity in respect of the calendar year;
B
is the variable assessment amount determined under subsection (3) for the participating entity in respect of the calendar year; and
C
is the amount of any interim assessment made against the participating entity under subsection 140(4) of the Act during the calendar year.

Base assessment amount

(2) The base assessment amount for a participating entity in respect of a calendar year is

Variable assessment amount

(3) The variable assessment amount for a participating entity in respect of a calendar year is

Assets of subsidiaries

(4) For the purpose of this section, the value of a participating entity’s total assets excludes the value of the assets of any subsidiary of the entity that is itself a participating entity.

Accredited third-party service providers

60 For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed, in respect of a calendar year, against an individual or entity that was an accredited third-party service provider at any time during that calendar year is $10,000, less the amount of any interim assessment that was made against the accredited third-party service provider under subsection 140(4) of the Act during the calendar year.

External complaints body

61 (1) For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed in respect of a calendar year against the external complaints body is, subject to subsection (2), $50,000, less the amount of any interim assessment that was made against the external complaints body under subsection 140(4) of the Act during the calendar year.

Partial calendar year

(2) The amount that is to be assessed in respect of a calendar year against a corporation that was designated as the external complaints body for only a portion of that year is to be reduced proportionally.

Request for information

62 (1) For the purpose of subsection 141(1) of the Act, the period within which the requested information must be provided to the Bank is

Value of assets

(2) Despite subsections 59(2) and (3), if a participating entity fails to provide requested information about the value of its assets within the period referred to in paragraph (1)(a), the base assessment amount and variable assessment amount for that participating entity are to be determined as if the participating entity were a participating entity referred to in paragraph 59(2)(a).

Administrative Monetary Penalties

Designation of violations

63 The following are designated as violations under paragraph 155(1)(a) of the Act:

Coming into Force

S.C. 2026, c. 3, s. 224

64 (1) Subject to subsections (2) and (3), these Regulations come into force on the day on which section 44 of the Consumer-Driven Banking Act comes into force, but if they are registered after that day, they come into force on the day on which they are registered.

S.C. 2026, c. 3, s. 224

(2) Sections 34 to 36, 38 to 55 and 63, other than subparagraph 63(a)(liii), come into force on the day on which section 76 of the Consumer-Driven Banking Act comes into force, but if these Regulations are registered after that day, those provisions come into force on the day on which these Regulations are registered.

S.C. 2026, c. 3, s. 224

(3) Sections 59 to 62 and subparagraph 63(a)(liii) come into force on the day on which section 140 of the Consumer-Driven Banking Act comes into force, but if these Regulations are registered after that day, those provisions come into force on the day on which these Regulations are registered.

Terms of use and Privacy notice

Terms of use

It is your responsibility to ensure that the comments you provide do not:

  • contain personal information
  • contain protected or classified information of the Government of Canada
  • express or incite discrimination on the basis of race, sex, religion, sexual orientation or against any other group protected under the Canadian Human Rights Act or the Canadian Charter of Rights and Freedoms
  • contain hateful, defamatory, or obscene language
  • contain threatening, violent, intimidating or harassing language
  • contain language contrary to any federal, provincial or territorial laws of Canada
  • constitute impersonation, advertising or spam
  • encourage or incite any criminal activity
  • contain external links
  • contain a language other than English or French
  • otherwise violate this notice

The federal institution managing the proposed regulatory change retains the right to review and remove personal information, hate speech, or other information deemed inappropriate for public posting as listed above.

Confidential Business Information should only be posted in the specific Confidential Business Information text box. In general, Confidential Business Information includes information that (i) is not publicly available, (ii) is treated in a confidential manner by the person to whose business the information relates, and (iii) has actual or potential economic value to the person or their competitors because it is not publicly available and whose disclosure would result in financial loss to the person or a material gain to their competitors. Comments that you provide in the Confidential Business Information section that satisfy this description will not be made publicly available. The federal institution managing the proposed regulatory change retains the right to post the comment publicly if it is not deemed to be Confidential Business Information.

Your comments will be posted on the Canada Gazette website for public review. However, you have the right to submit your comments anonymously. If you choose to remain anonymous, your comments will be made public and attributed to an anonymous individual. No other information about you will be made publicly available.

Comments will remain posted on the Canada Gazette website for at least 10 years.

Please note that communication by email is not secure, if the attachment you wish to send contains sensitive information, please contact the departmental email to discuss ways in which you can transmit sensitive information.

Privacy notice

The information you provide is collected under the authority of the Financial Administration Act, the Department of Public Works and Government Services Act, the Canada–United States–Mexico Agreement Implementation Act,and applicable regulators’ enabling statutes for the purpose of collecting comments related to the proposed regulatory changes. Your comments and documents are collected for the purpose of increasing transparency in the regulatory process and making Government more accessible to Canadians.

Personal information submitted is collected, used, disclosed, retained, and protected from unauthorized persons and/or agencies pursuant to the provisions of the Privacy Act and the Privacy Regulations. Individual names that are submitted will not be posted online but will be kept for contact if needed. The names of organizations that submit comments will be posted online.

Submitted information, including personal information, will be accessible to Public Services and Procurement Canada, who is responsible for the Canada Gazette webpage, and the federal institution managing the proposed regulatory change.

You have the right of access to and correction of your personal information. To seek access or correction of your personal information, contact the Access to Information and Privacy (ATIP) Office of the federal institution managing the proposed regulatory change.

You have the right to file a complaint to the Privacy Commission of Canada regarding any federal institution’s handling of your personal information.

The personal information provided is included in Personal Information Bank PSU 938 Outreach Activities. Individuals requesting access to their personal information under the Privacy Act should submit their request to the appropriate regulator with sufficient information for that federal institution to retrieve their personal information. For individuals who choose to submit comments anonymously, requests for their information may not be reasonably retrievable by the government institution.