Canada Gazette, Part I, Volume 160, Number 26: Consumer-Driven Banking Regulations
June 27, 2026
Statutory authority
Consumer-Driven Banking Act
Sponsoring department
Department of Finance Canada
REGULATORY IMPACT ANALYSIS STATEMENT
(This statement is not part of the Regulations.)
Executive summary
Issues: When making purchases or carrying out banking tasks, consumers, including individuals and businesses, generate a stream of information based on their transactions. In Canada, this financial data is predominantly held and controlled by incumbent financial institutions. Recognizing the value of leveraging this data, financial technology businesses (fintechs) have developed applications that utilize consumers’ financial records to provide innovative products and services. Canada has not yet implemented a consumer-driven banking framework to ensure that this financial data is shared securely and with adequate oversight. A lack of requirements and supervision for these activities stifles innovation and competition, as well as poses significant security, liability, and privacy risks for Canadians and Canadian businesses who must provide their banking credentials to fintechs to access these services.
Description: The Consumer-Driven Banking Act (the Act), which received royal assent in March 2026, and the proposed Consumer-Driven Banking Regulations (the proposed Regulations), introduce a secure framework overseen by the Bank of Canada that enables Canadian individuals and businesses to share their financial data with accredited service providers of their choice. The proposed Regulations include requirements related to accreditation, security, national security, authentication and consent, reporting, record keeping, framework transparency, technical standards, assessments, and violations. The proposed Regulations also include the timelines and information requirements to support the national security review process related to the Minister of Finance’s national security authorities under the Act.
Rationale: The proposed Regulations are required to support the implementation of the Act. The objectives of the consumer-driven banking framework, informed by the Act and proposed Regulations, are to promote competition and innovation in the financial sector, improve financial outcomes for Canadian consumers and businesses, ensure that consumers can share their data securely and are protected while doing so, and strengthen Canada’s position in the global digital economy. The inclusion of national security authorities under the Act and the proposed Regulations supports the integrity of the financial system, making it more safe and secure for consumers to share financial data.
The development of Canada’s consumer-driven banking framework was informed by lessons learned from leading jurisdictions that have implemented successful open banking frameworks, as well as extensive stakeholder engagement involving financial institutions, fintechs, provincial governments, consumer groups, academics, and domestic policy experts. Together, this process provided the evidence base for adopting a government-led, legislated framework overseen by the Bank of Canada, with a role for provincial and territorial governments in overseeing provincially regulated entities that opt in to the framework in appropriate circumstances.
The proposed Regulations would result in an estimated total cost of $457.7 million total present value (TPV) over a 10-year period. The estimated monetized benefits of the proposed Regulations are $13.2 billion TPV over a 10-year period. All Canadians would benefit from the increased access to innovative financial services and economic growth driven by the implementation of the framework. Thus, preliminary estimates of monetized benefits are illustrative and non-exhaustive, and many of the benefits cannot be quantified at this time.
Issues
When making purchases or carrying out banking tasks, consumers, including individuals and businesses, generate a stream of information based on their transactions. In Canada, this financial data is predominantly held and controlled by incumbent financial institutions, including the country’s largest banks. Recognizing the value of leveraging this data, financial technology businesses (fintechs) have developed applications that utilize consumers’ financial records to provide innovative products and services. However, the current lack of regulatory framework overseeing these activities has limited innovation and competition, leading to untapped potential across the Canadian digital economy.
About nine million Canadians currently access financial data sharing services by providing their confidential banking credentials in a process known as screen scraping. This unregulated and technologically unsecure practice can negatively impact consumers by posing increased security, liability and privacy risks, leaving them without recourse if something goes wrong, such as a data leak of their personal or financial information. The absence of a framework to screen for hostile actors seeking to target consumer data sharing technologies for their own objectives poses a threat to national security and puts Canadians at risk.
To promote financial sector competition, establish secure and efficient financial data sharing, and address the risks posed by screen scraping, the Government introduced the Consumer-Driven Baking Act (the Act), which received royal assent in March 2026. The Act introduces a new supervisory regime administered by the Bank of Canada for entities participating in the framework, including federal and provincial financial institutions, fintechs, and other businesses, as well as third-party service providers, which may assist participating entities by carrying out certain activities on their behalf. The Act also provides the Minister of Finance with authorities to address national security risks posed by participating entities and third-party service providers.
The proposed Consumer-Driven Banking Regulations (the Regulations) are required to bring the Act into force and would prescribe key elements and criteria for entities to become accredited by the Bank of Canada, comply with the Act, and for the Bank of Canada to promote compliance with the Act and Regulations.
Background
Consumer-driven banking, also known as open banking, refers to secure frameworks that enable individuals and businesses to share their financial data with approved service providers of their choice. This is achieved through robust regulatory requirements and oversight of businesses that use application programming interfaces (APIs), a type of technology that provides a more secure connection between entities, to share consumer financial information with consent. Sharing financial information in this way gives consumers greater control over their data while promoting a competitive, innovative, and secure financial sector and digital economy.
In recognition of the merits of safe and secure financial data sharing, governments across the globe, including those in Australia, New Zealand, Brazil, the European Union, India, and the United Kingdom, have implemented systems of open banking. Certain jurisdictions, such as Australia, have gone one step further and adopted an economy-wide approach to data sharing that began with open banking, grew to energy, and will expand to other sectors, such as telecommunications.
As part of a broader effort to enhance rights and protections for consumers in a digital economy, the Government of Canada announced a Review into the Merits of Open Banking in Budget 2018. The Advisory Committee on Open Banking (Advisory Committee) was appointed to guide the review. In 2019, Finance Canada released a consultation paper exploring whether open banking should be considered for Canada. Following its work, the Advisory Committee concluded that open banking could deliver benefits to consumers and found that a framework with established rules would manage risks and support a more innovative and competitive financial services sector.
The Advisory Committee was then reappointed by the Government to conduct a review into the implementation of open banking in Canada, which resulted in a final report in 2021. The Advisory Committee identified common rules (privacy, security, and liability), accreditation, and technical standards as the core elements necessary for a functioning open banking system in Canada. The report made 34 recommendations, one of which was the appointment of an ’Open Banking Lead’ to convene industry to develop accreditation criteria and common rules. The Advisory Committee also recommended that the initial scope be limited to read access functions (i.e. providing only for viewing and sharing of data between accredited parties), and that the system be built to allow the scope to be expanded to include new types of data and “write access” functions (i.e. the ability to initiate a financial transaction or other action from an account, such as opening or closing the account) once the system is established.
In early 2022, the Government appointed Abraham Tachjian, a Canadian lawyer with international banking experience, as the Open Banking Lead (the Lead) with a mandate to develop a made-in-Canada regime based on the recommendations in the Advisory Committee’s final report. The Lead established four working groups on privacy, security, accreditation, and liability with balanced representation from industry, consumer groups, and government regulators. The Lead also established a steering committee to discuss issues related to governance and technical standards. In late 2023, the Lead concluded his term by providing a recommendation to the Minister that the Government move forward, through legislation, to implement a system of open banking, with a phased approach to scope (data, participants, and functionality) and adopt a single technical standard and timeline for phasing out screen scraping.
In addition to studying the benefits of financial innovation, including open banking frameworks, the Government of Canada has continued to evaluate and assess the evolving financial sector risk environment shaped by new technologies and geopolitical events. For instance, the Office of the Superintendent of Financial Institutions’ (OSFI) 2025-2026 Annual Risk Outlook indicates that state actors and state-sponsored actors may target Canadian institutions for financial gain, to advance their political objectives, and disrupt the functioning of Canada’s financial infrastructure and economy. Canada’s consumer-driven banking framework seeks to mitigate these risks by providing the Minister of Finance with adequate national security authorities.
The Government introduced the first part of the consumer-driven banking legislation through the Budget Implementation Act, 2024, No. 1. The legislative framework was completed through Budget Implementation Act, 2025, through the inclusion of provisions for accreditation and common rules that address security, national security, liability, and consent. Budget Implementation Act, 2025 also reinforced the importance of data-driven innovation and the role it plays in competition through amendments to the Personal Information Protection and Electronic Documents Act (PIPEDA) that enshrined an economy-wide right to data portability for all Canadians in sectors that develop secure and interoperable frameworks. Consumer-driven banking will be a first iteration of such a framework.
Further to announcing the completion of the consumer-driven banking legislative framework, Budget 2025 also announced the Government’s intention to move quickly to advance regulation to implement the framework, and to undertake consultation and policy work to advance a second phase of consumer-driven banking that considers broader scope and functionality, including write access. It also announced delegation of oversight of the Act to the Bank of Canada, building on its oversight of payment service providers (PSPs) under the Retail Payment Activities Act (RPAA).
The RPAA introduced a retail payment supervisory regime for PSPs, such as payment processors and digital wallets. Provisions requiring PSPs to register with the Bank of Canada came into force in November 2024 while substantive requirements of the RPAA — establishing operational risk management and funds safeguarding frameworks — came into force in September 2025. Leveraging the Bank of Canada’s existing resources and expertise will enable the Government to advance its goals for consumer-driven banking quickly and streamline processes for participants of both regimes.
Consumer-Driven Banking Act
The core elements of Canada’s consumer-driven banking framework (the framework) are set out in the Act, which establishes obligations falling broadly into the following categories: governance, scope, accreditation, common rules (consent, liability, security), national security, technical standards, framework transparency, and a prohibition on screen scraping.
Governance
To improve government efficiency and align with existing oversight for the RPAA, the responsibility for implementation and oversight of the Act is delegated to the Bank of Canada. To facilitate participation of provincially regulated financial institutions, the governance model is structured to allow provincial financial institutions, including credit unions and crown corporations that offer deposit-taking services to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.
To enhance federal, provincial and territorial collaboration, the Act authorizes the Minister of Finance to designate the supervision of certain legislative provisions to a provincial authority when certain criteria are met. The provincial authority will supervise the obligations and work with the Bank of Canada for necessary enforcement. The Act also establishes a federal, provincial and territorial advisory committee to advise on the implementation and evolution of the framework.
Scope
The consumer-driven banking framework’s scope is divided into three elements: (i) which entities can participate, (ii) the breadth of data sharing, and (iii) functionality. Participation in the framework will initially be mandated for specified large banks based on a threshold for retail volume. Remaining federally regulated financial institutions, as well as credit unions, crown corporations that offer deposit-taking services, PSPs registered under the RPAA, and other entities seeking accreditation, would be able to opt in, provided they meet the requirements for entry and demonstrate adherence to the technical standard and security specifications. Under the Act, all participating entities are required to share consumer-authorized in-scope data (including data related to deposit accounts, payment products, investment accounts, and lending accounts) and may not impose a charge for doing so, nor for obtaining, renewing or withdrawing consent. Derived data, defined as information about a consumer, product, or service that has been significantly enhanced by a participating entity to increase its usefulness or commercial value, is excluded from the Act. Framework functionality will be limited to “read only” access under phase one.
Accreditation
The Act provides the Minister of Finance the authority to mandate the participation of certain banks in the framework and sets out accreditation processes for other federally regulated financial institutions, provincially regulated financial institutions, RPAA registered PSPs, and other entities to ensure that only those that meet certain requirements can participate in the data-sharing ecosystem. The Act also requires participating entities that wish to outsource certain tasks related to consent management, authentication management, and movement of data to use accredited-third party service providers (ATPSPs) that meet applicable accreditation requirements. The Act requires the Bank of Canada to publish a list of all participating entities and ATPSPs in a central public registry.
Common rules
Common rules are established in the Act around consent, liability, and security for all participants. These rules include requiring consent and revocation processes that are clear, simple, and not misleading, establishing that liability flows with the data, and setting out clear security requirements. The Act also provides the Minister of Finance with the authority to designate an independent, not-for-profit, external complaints body overseen by the Bank of Canada to resolve consumer-driven banking complaints free of charge to the consumer. All participating entities must be a member of the external complaints body. The Act authorizes the Minister to exempt entities from this membership requirement, provided they are members of a recognized provincial equivalent.
National security
The Act provides authorities to the Minister of Finance to address risks related to national security that could be posed by participating entities and ATPSPs. The Minister will be able to review applicants and accredited entities and issue a directive to the Bank of Canada to refuse, suspend, or revoke access to the framework for national security reasons. The Minister may also require an undertaking from, or impose terms and conditions on, an applicant, participating entity, or ATPSP for national security reasons. These authorities align with existing financial sector statutes, such as the RPAA and the Bank Act.
Technical standards
The Act requires participating entities to implement a single technical standard set by a technical standards body to provide certainty to framework participants and supervisors. The technical standards body will be designated according to the factors and processes set out in the Act. The designation factors include being meaningfully Canadian; having a governance structure that is fair, open, and accessible, with independent decision making and an ability to exercise powers and act in a manner consistent with the objectives of the Act; and ensuring the standard itself is safe, secure, and interoperable. The Act also authorizes the Minister to consider any other factor deemed relevant and authorizes that regulations may be made to include additional criteria. The Act includes authorities for the Minister of Finance to designate and revoke the technical standards body, through a Ministerial Order, and other criteria to inform the assessment of candidates for said body.
Framework transparency
In order to foster transparency and trust, the Act requires the Bank of Canada to publish consumer-driven banking-related information to inform participating entities and the public. Regulations specifying the precise nature of the information to be published are not necessary for the operationalization of the framework, but may be advanced in the future subject to further consultation and engagement.
Prohibition of screen scraping
The Act includes a prohibition on screen scraping that is not required to operationalize the broader framework and will not be brought into force until broader consultation and policy development have taken place. The Department of Finance will continue to consult with stakeholders to determine an appropriate timeline for bringing the prohibition into force and parameters for the ban that would be articulated in regulation at a future date.
Objective
The goals of Canada’s consumer-driven banking framework, informed by the Act and proposed Regulations, are to promote competition and innovation in the financial sector, improve financial outcomes for Canadian consumers and businesses, ensure that consumers can share their data securely and are protected while doing so, and provide the Government with the information needed to protect Canadians and Canadian financial sector infrastructure from national security risks. In other countries, regulated frameworks have proven effective at achieving these policy goals by empowering consumers, enhancing data accessibility, and supporting new financial service providers and business models within an established regulatory framework informed by appropriate checks and balances.
The development of the consumer-driven banking framework, including the proposed Regulations, was guided by three public policy objectives:
- Competition, innovation, and economic growth: Accelerating the growth of Canada’s digital economy while supporting new entrants, existing financial institutions, and homegrown innovators. Regulated data-sharing will preserve Canada’s secure and stable financial sector, while enabling innovation and competition.
- Consumer financial well-being and protection: Ensuring Canadians can securely share their data with more trusted financial service providers. Regulated data sharing will give consumers control over their data and establish consistent rules that limit consumers’ liability, ensure data is kept safe while in transit, and address outdated practices like screen scraping.
- Safety and soundness: Strengthening the overall integrity of the financial sector by addressing risks related to existing data sharing practices. Establishing a robust accreditation process and oversight framework will ensure that participating entities meet high standards of security and reliability, supporting stability and trust in the financial sector.
Description
The proposed Regulations would operationalize the Consumer-Driven Banking Act, ultimately enabling consumers, including individuals and businesses, to securely share their financial data through an API to approved service providers of their choice. The specific requirements informing the proposed Regulations are set out below.
Data scope
The breadth of data sharing is broadly defined in the Act. It specifies that, at the request of a consumer, participating entities will be required to share both data provided by a consumer and product data related to deposit accounts (chequing and savings), payment products, investment accounts (registered and non-registered),footnote 1 and lending accounts (secure and unsecured).footnote 2 The proposed Regulations would provide further clarity regarding the scope of data that must be made available for sharing to consumers with regards to consumer profile data, account data, including balance and transaction data, and product data.
Proposed consumer profile data would include information provided by the customer in the context of account opening, identification, and verification (such as, but not limited to, name, address, date of birth, and employment information). Proposed account data for in-scope data sharing would include information identifying the accounts held by a consumer (such as, but not limited to, the number of accounts held, and identifiers or numbers used to identify those accounts), account agreement and product document information (such as, but not limited to, information outlining the contractual terms and conditions applicable to the consumer’s account), balance data (such as, but not limited to, the value held in, owing on, or otherwise associated with one or more accounts held by the consumer, including balances presented on periodic statements or bills), and transaction data (such as, but not limited to, the information relating to financial activity in respect of the account, including recent, pending, pre-authorized, and historical transactions). Finally, proposed product data would include information related to the financial products and services offered by participating entities to the consumer.
Accreditation
The Act provides for an accreditation process overseen by the Bank of Canada to ensure that only entities that meet certain requirements, in accordance with the proposed Regulations, can participate in the framework. Banks mandated to participate in the framework are not subject to the accreditation process.
The proposed Regulations set out criteria for four pathways of accreditation specific to applicant entity type that must be demonstrated through submitting required material to the Bank of Canada using the electronic system provided by the Bank of Canada. The Bank of Canada will develop and publish guidelines on accreditation application criteria and processes ahead of the Act’s coming into force. Accreditation criteria for each pathway include:
- Non-streamlined accreditation: The proposed Regulations would require entities applying through this pathway, such as fintechs, to have a place of business in Canada, and demonstrate how their insurance or comparable guarantees cover risks associated with the management of consumer-driven banking data. Applicants would be required to submit organizational and operational information including contact information, organizational structure, regulatory or supervisory oversight standing in other jurisdictions that have implemented consumer-driven banking frameworks, as well as evidence of technical standard adherence, complaints procedures and consent management processes. The proposed Regulations would also require applicants to implement a policy under which all individuals with significant responsibility for its consumer-driven banking activities are regularly assessed for integrity and good character and for assessed individuals to report any changes in their circumstances that could affect that assessment to their employer to help ensure that these key personnel remain suitable on an ongoing basis. The proposed Regulations would not prescribe a specific assessment methodology but would require entities to establish an internal policy for ongoing assessment. Any such assessments would need to be carried out in a manner consistent with applicable privacy and employment law requirements. In addition, the proposed Regulations would require applicants to demonstrate compliance with baseline security requirements, including incident management and response, system and application security, access control and authentication, data protection and encryption, network and infrastructure security, third-party and cloud security, and security awareness and training.
- Streamlined accreditation for entities registered under the RPAA: The proposed Regulations would provide a streamlined accreditation stream for PSPs already registered under the RPAA. The proposed Regulations would require RPAA registered PSP applicants to declare that they have a place of business in Canada, and demonstrate how their insurance or comparable guarantees cover risks associated with the management of consumer-driven banking data. PSPs would be required to reaffirm organizational and operational information including contact information, as well as provide regulatory or supervisory oversight standing in other jurisdictions that have implemented consumer-driven banking frameworks, organizational structure, and evidence of technical standard compliance and consent management process. The proposed Regulations would also require RPAA registered applicants to develop and apply a policy to ensure the integrity and good character of key personnel involved in activities related to the Act, as well as demonstrate compliance with baseline security requirements.
- Accreditation for federal and provincial financial institutions: The proposed Regulations would require federal financial institutions not mandated by the Minister, such as banks, credit unions, and insurance companies, as well as provincial financial institutions seeking accreditation to submit organizational and operational information including contact information, regulatory or supervisory oversight standing in other jurisdictions that have implemented consumer-driven banking frameworks, organizational structure, declaration of compliance with security requirements, and evidence of technical standard compliance. Federal and provincial financial institutions are already subject to stringent security requirements under other regulatory frameworks. As such, federal and provincial financial institutions applying for accreditation would need to declare that they have implemented these security requirements and are in good standing vis-Ă -vis these requirements with their respective regulators.
- Accreditation for third-party service providers: The proposed Regulations would require prospective third-party service providers to declare that they have a place of business in Canada and to submit organizational and operational information including contact information, regulatory or supervisory oversight standing in other jurisdictions that have implemented consumer-driven banking frameworks, organizational structure, and the activities under the Act they intend to perform on behalf of participating entities, and to develop and apply a policy to ensure the integrity and good character of key personnel.
Regardless of accreditation pathway, all applicants would need to submit a prescribed accreditation fee to the Bank of Canada. The proposed Regulations set this fee at $2,500, to be adjusted for inflation and rounded to the nearest $100 on a yearly basis. There is also a separate annual assessment fee paid by all participating entities, as outlined in the section below.
The Bank of Canada will have the authority to deny, suspend, or revoke the accreditation status of any participating entity or third-party service provider (other than a mandated bank) and will be required to maintain a public registry of these decisions. The proposed Regulations would provide 30 days for applicants to request a review of a refusal to accredit and to participating entities and ATPSPs who have received a notice of intent to revoke their accreditation status. The Bank of Canada would be provided with 120 days to then provide a decision to the applicant or participating entity or ATPSP. The proposed Regulations provide the applicant or participating entity or ATPSP with 30 days to appeal the decision to federal court.
Accreditation is not a static obligation and there is no requirement for accredited entities to renew accreditation status once provided. Participating entities and ATPSPs would be required to keep the accreditation information up to date and continue to meet applicable accreditation requirements and criteria on an ongoing basis. Any changes to the accreditation requirements or information submitted in the course of applying for accreditation would require a notice of change to be submitted to the Bank of Canada, as described in the duties of participating entities and ATPSP sections below. In the case where a participating entity or ATPSP no longer meets the accreditation requirements, the Bank of Canada may issue a notice to suspend or revoke their accreditation status.
The proposed Regulations would specify that the public registry of participating entities and ATPSPs be updated in real time. The registry would include the name and contact details of each participating entity and ATPSP, including the date they were mandated to participate or were accredited, their status of accreditation (including suspension and revocation), and the contact information for the individual they have appointed to oversee complaints related to their participation in the framework. The registry would also include a functionality that other participating entities can use to access a developer portal to facilitate data sharing, and a list of activities offered by each ATPSP.
National security safeguards
The proposed Regulations related to national security support the Minister of Finance’s authorities. The national security provisions in the Act and proposed Regulations are modelled on and consistent with other financial sector statutes, such as the Bank Act and the RPAA.
The Act contains national security safeguards that enable the Minister to review accreditation applicants, participating entities, and ATPSPs for risks related to national security. Under any accreditation pathway, in accordance with the Act, all applicants would need to submit information necessary for national security purposes to the Bank of Canada. As set out in the proposed Regulations, this would include identifying information about the applicant, its owners, senior officers, directors, and other persons with significant influence over the applicant (including creditors and state-owned enterprises), information about personal data collection, use, and sharing with third parties, and information about relevant corporate and business relationships.
The proposed Regulations would provide the Minister with 60 days to decide to review an accreditation application for national security concerns and allow the Minister to extend the decision period for additional 60-day periods, if necessary. Should the Minister decide to proceed with a national security review, the proposed Regulations would specify that the review must be conducted within 180 days and that the period for conducting the review may be extended for additional 180-day periods at the discretion of the Minister. In accordance with the Act, if a national security review is required, the Minister would inform the Bank of Canada, which would in turn inform the applicant of the Minister’s decision. Should the Minister request additional information related to the national security review, the proposed Regulations would specify that the applicant would have 30 days to provide the requested information to the Bank of Canada.
Upon completion of the review, the Act provides that the Minister may issue a directive to the Bank of Canada to refuse an accreditation application submitted by a participating entity or ATPSP. The Minister may also require an undertaking from, or impose terms and conditions on, an applicant, participating entity or ATPSP for reasons related to national security.
Relatedly, the proposed Regulations would specify that an applicant, participating entity, or ATPSP would have 30 days to request a review of the Minister’s decision to direct the Bank to refuse accreditation or the Minister’s issuance of a notice of intent to direct the Bank to revoke accreditation.
Duties of participating entities
Once admitted to the framework, the Act provides that participating entities must fulfill various requirements to uphold consumer protection measures, maintain their accreditation status, demonstrate their compliance with the Act, and abide by common rules related to privacy and consent, liability, security, and integrity. The proposed Regulations would specify the requirements as set out in the Act related to the display of signs, notices, record keeping, annual reporting, common rules, and data sharing as follows:
- Display of sign: The Act requires participating entities to display a visual identifier or sign indicating they are a participating entity in the framework, in a manner prescribed by the Bank of Canada, in their physical and digital properties. The sign would serve as a consumer protection measure, ensuring that consumers can clearly identify the entities with whom they may safely share their financial data. The proposed Regulations would provide further clarity, including that physical signs would need to be visible during business hours in the main customer areas of the business. The proposed Regulations would also specify that the location of the sign cannot be used in a manner that is misleading about the accreditation status of a given entity.
- Notice of change: The Act provides that participating entities must notify the Bank of Canada of changes that would impact the accreditation outcome had that change been in place during the time that the accreditation application was being reviewed by the Bank of Canada. The scope of these changes is related to the participating entity itself or the activities it performs under the Act. The proposed Regulations would specify that the changes that must be reported include those related to information submitted during accreditation, as well as changes to the ATPSPs with which they maintain a contract to perform activities under the Act. Reporting timelines are established to correspond with the urgency and/or availability of the information. Accordingly, changes with more immediate or pressing impacts must be reported as soon as feasible, while all other changes must be reported within 30 days after they occur. The Bank of Canada will develop and publish guidelines on participating entity change notices ahead of the Act’s coming into force.
- Record keeping: The proposed Regulations would require a participating entity to maintain sufficient records to demonstrate its compliance with the Act and the Regulations. Records must be retained in an electronic form that is intelligible to the Bank of Canada for a period of five years, unless otherwise specified in a condition or undertaking. The proposed Regulations would also require that measures be taken to protect records from loss, destruction, falsification, inaccuracies, and access by unauthorized persons.
- Annual reporting: The Act provides that participating entities must submit an annual report to the Bank of Canada in the form and manner specified by the Bank of Canada. The proposed Regulations would require the annual report to include information related to data sharing performance and availability, notices of change, changes that have a significant impact on security safeguards, changes to policies and procedures, summaries of any breaches of security safeguards, a declaration that the entity is still in compliance with the technical standards and security safeguards, a description of how the entity meets the security safeguards, and a description of financial performance metrics to support risk-based supervision.
- Security: The proposed Regulations build on the requirements in the Act to provide robust safeguards for data and specify requirements related to the security breach notice and duty to investigate, as follows:
- Security breach notice: The proposed Regulations would specify that a report submitted to the Bank of Canada regarding a breach of the security safeguards involving consumer data that is under the participating entity’s control must be made as soon as feasible after the breach occurs and include relevant information about the circumstances, timing, and next steps for handling the breach. In the circumstance that a breach creates a risk of significant harm to the consumer, defined in the Act as bodily harm, humiliation, damage to reputation or relationships, loss of employment, of business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property, the consumer must be notified directly or indirectly, as appropriate.
- Duty to investigate: The proposed Regulations would require reporting on every investigation into a breach of security safeguards, including the incident’s cause, impacts, and actions taken to prevent the incident from reoccurring. These reports must be made as soon as feasible using the electronic system provided by the Bank of Canada.
- Consent: The proposed Regulations specify various consent management requirements under the Act with respect to use of data, record of consent, consent renewal, and data deletion, as follows:
- Use of data: The proposed Regulations would create a limited set of circumstances where it is acceptable for a participating entity to use a consumer’s data that has been shared under the framework for a purpose that is different from the purposes listed when express consent was initially obtained. The list of exceptions adapts existing PIPEDA exemptions to consumer-driven banking activities that permit organizations to use personal information without the knowledge or consent of the individual. The exceptions are related to investigations of contraventions of the law; emergencies that threaten the life, health or security of an individual; or publicly available data. The Bank of Canada will develop and publish guidelines on data usage and consent management ahead of the Act’s coming into force.
- Record of consent: Participating entities would be required to keep and provide a record of express consent to the Bank of Canada. This record must be retained in a form that is or can readily be made intelligible to the Bank for a period of five years, unless otherwise specified in a condition or undertaking. The proposed Regulations would also require that measures be taken to protect records from loss, destruction, falsification, inaccuracies, and access by unauthorized persons.
- Consent renewal: The proposed Regulations would specify the exceptional circumstances in which a consent renewal must be triggered by a participating entity outside of the normal period of valid consent (no longer than 12 months). These circumstances include when a participating entity becomes aware that a consumer’s authentication information has been stolen or otherwise exposed to imminent risk, when a participating entity becomes aware of a significant change in the consumer’s circumstance, and when there is a significant change to the participating entity’s circumstance. Significant changes would be defined as exceptional circumstances where it could be reasonably called into question whether the consumer would provide consent given the new facts provided to them. In these circumstances, participating entities receiving data would be required to initiate renewal of consent as soon as feasible after the entity becomes aware of the circumstance. Participating entities providing data would be required to request — as soon as feasible after becoming aware of the circumstance — that the participating entity receiving the data initiate a renewal.
- Data deletion: The proposed Regulations would clarify that a participating entity’s duty to delete data at a consumer’s request is not required when consumers have provided consent for participating entities to use modified versions of their data that have been irreversibly and permanently modified so as to ensure that there is no reasonably foreseeable risk that the consumer can be identified from it, whether directly or indirectly, by any means. Under the proposed Regulations, participating entities could refuse or delay a consumer’s request to delete data if a request is refused in respect of a time-bound, legally imposed requirement (e.g. legal data retention period. The participating entity is required to inform the requestor, as soon as feasible, in writing of the refusal and the reasons for it and), the requestor must be informed of the time at which the entity will be able to delete their data. No further action would be required by the consumer to complete the request at that time.
- Authentication: Under the Act, once a participating entity requesting data has obtained a consumer’s consent, the data provider is required to authenticate the consumer before sharing consumer data. The responsibility for obtaining consumer consent and for authenticating the consumer is divided between the data requester and the data provider, respectively. The proposed Regulations would require participating entities providing data to employ identity and access controls, including multi-factor authentication. The proposed Regulations further specify that reauthentication is also required in circumstances where consent renewal is obligated.
- Data sharing: The proposed Regulations would further specify data sharing requirements set out in the Act. Participating entities would be required to verify the identity of the other participating entity prior to sharing data by ensuring that they are on the Bank of Canada registry and that their status on the registry does not place conditions on their ability to provide or receive data. The proposed Regulations would also create exceptions to the duty to share by defining a list of circumstances where a participating entity can refuse an initial sharing request or stop providing data despite valid consumer consent. The proposed Regulations would specify that these circumstances include instances where there are reasonable grounds to believe that sharing data would cause physical, psychological or financial harm to the consumer, instances where there are reasonable grounds to believe that sharing data would create risks to the security, integrity, or stability of the framework or a participating entity’s information and communication technology systems, and instances where consumer accounts have been blocked or suspended. Participating entities that invoke one of these exceptions (as well as exceptions that are invoked in relation to consent renewal initiations or requests to initiate a renewal) would be required to inform the other participating entity that is requesting or providing the data, as well as the Bank of Canada to ensure appropriate application. The Bank of Canada will develop and publish guidelines on data sharing prior to the Act’s coming into force.
- Minimum service level standards: The Act provides for the establishment of minimum service-level requirements to ensure that financial data is shared in a consistent manner across participating entities. The proposed Regulations would set the baseline expectations for uptime by requiring endpoints to be available 99.5% per month; response times to be reasonable and consistent with generally accepted standards as established in other jurisdictions; rate limitations to only be permissible for reasons of technical stability or security; and participating entities to make available a minimum of 24 months of consumer data upon request. The requirement to provide 24 months of history gives consumers and participating entities enough data to support core use cases, such as budgeting, credit building, and better credit adjudication, while also capturing seasonal and recurring financial patterns that shorter windows miss. The proposed Regulations further specify that data availability requirements do not apply to planned outages, which may only occur where the Bank of Canada is notified at least one week in advance for normal outages and without advanced notification if required to resolve a critical service or security issue. The Bank of Canada will develop and publish guidelines on minimum service-level standards ahead of the Act’s coming into force.
- Liability: The proposed Regulations provide additional clarity on specific responsibilities related to providing and receiving data to ensure the liability structure is robust and that participating entities are clear about what they are accountable for when conducting each activity. This includes clarifying that participating entities requesting data are responsible for obtaining consumer consent and securely receiving the data they request, and that participating entities that are providing the data are responsible for authenticating the consumer and securely providing the requested data. This division of responsibility would delineate which participating entity would be liable to the consumer should there be a direct financial loss in the course of a data-sharing transaction. The proposed Regulations also require participating entities to advise consumers of reasonable measures they can take to safeguard authentication information and to inform them of consequences related to gross negligence or gross fault in Quebec.
- Notice of framework exit: The Act requires former participating entities to notify consumers when their accreditation has been revoked. This would apply in both involuntary circumstances, such as when accreditation has been revoked by the Bank of Canada due to contraventions of the Act or proposed Regulations, and voluntary circumstances, such as when a participating entity discontinues a consumer-driven banking-related business line such as a budgeting app, ceases operations due to a merger or consolidation, or no longer has sufficient financial resources to continue operating. The proposed Regulations specify that these notices must be made in writing and include contact information for an individual at the former participating entity who may provide additional information about the revocation; and, in the case of involuntary revocation, the reasons for it; the impact it will have on the consumer; and the date on which the revocation takes effect. The proposed Regulations also require participating entities to inform consumers, through notices, that requests for data deletion should be submitted to the participating entity as soon as feasible. If consumers do not contact the participating entity to request deletion, the participating entity would be required to retain the information for five years in accordance with record-keeping requirements. The proposed Regulations further specify that participating entities voluntarily requesting revocation of accreditation would need to provide notice to consumers at least 30 days prior to making the request, and that notices for revocations for other reasons would need to be made as soon as the participating entity becomes aware of the revocation.
Duties of ATPSPs
The Act provides that participating entities can enter a contract with an ATPSP to outsource prescribed activities while still maintaining overall liability for those activities. Nonetheless, to preserve the integrity of the framework, the Act requires ATPSPs to undertake duties both while they participate in the framework, as well as when they exit it. The proposed Regulations would further specify the requirements as set out in the Act as follows:
- Record keeping: The proposed Regulations specify the types of records that ATPSPs must maintain, including records demonstrating compliance with the Act and the Regulations. ATPSPs would also be required to keep records of their contracts with participating entities, as well as, to the extent available, records of their policies and procedures insofar as they relate to the services provided to the participating entity with which they maintain a contract. All records must be retained for a period of five years, aligning with record-keeping and retention requirements under comparable regulatory frameworks, such as the RPAA regulations. In addition, the proposed Regulations require that records be maintained in electronic form in a format that is intelligible to the Bank of Canada, and that ATPSPs take reasonable measures to protect records against risks such as loss, destruction, and inaccuracy.
- Notice of change: The Act requires ATPSPs to notify the Bank of Canada of certain changes to their accreditation criteria, including updates to the information provided in their application (such as changes to their address) and changes affecting how they meet accreditation requirements (such as maintaining a place of business in Canada), and activities they perform on behalf of participating entities within the framework. The proposed Regulations specify that a notice is to be submitted in the case of changes to applicant name and contact information, regulatory oversight in other jurisdictions that maintain consumer-driven banking frameworks, organizational structure, activities they perform on behalf of participating entities, and in persons subject to the ATPSP’s integrity and good character policy. The proposed Regulations would establish two reporting timelines for notices of change. Changes with more immediate or pressing impacts must be reported as soon as feasible, while all other changes must be reported within 30 days after they occur.
- Notice of framework exit: The Act requires former ATPSPs to notify participating entities as soon as feasible when their accreditation status has been revoked under both voluntary and involuntary circumstances. The proposed Regulations specify that these notices must be made in writing and include the name and contact information for the former ATPSP, a description of the impact on the participating entity, the date on which the revocation takes effect, and, in the case of involuntary revocation, the reasons for revocation.
Technical standards body reporting
The Act requires the designated technical standards body to submit an annual report to the Bank of Canada to demonstrate that it remains compliant with the designation factors considered by the Minister. The annual report also provides the information necessary for the Bank of Canada to inform its advice to the Minister regarding the technical standards body. The proposed Regulations would require the annual report to include information about security features added to the standard and information relating to overall standard performance. The proposed Regulations would require the technical standards body to provide the Bank of Canada with any changes that were made and could be relevant to the body’s designation under the Act.
Evidentiary privilege
The Act provides a regulation-making authority to enable the Minister of Finance, the Governor of the Bank of Canada, and the Attorney General of Canada to use prescribed supervisory information as evidence during civil litigation and proceedings. The proposed Regulations divide the information into three categories based on the document’s objective. These categories include information issued or prepared by the Bank of Canada in connection with its supervision of consumer-driven banking activities; correspondence related to accreditation, notices, letters, and compliance agreements; and directions given to participating entities, ATPSPs, the external complaints body, or the technical standards body.
Assessment fees
Once the framework is operational, the Bank of Canada will recover the costs associated with the administration of the Act via assessments on participating entities, accredited third-party service providers, and the external complaints body. The proposed Regulations would include an annual assessment regime applicable to participating entities, ATPSPs, and the external complaints body; a tiered assessment formula for participating entities consisting of a base fee and a variable fee component linked to total asset value; and provisions governing assessments for ATPSPs and the external complaints body. The proposed Regulations would specify that participating entities would be required to report, on an annual basis, the information necessary for the Bank of Canada to administer both the fixed and variable portions of the assessment fee, including the participating entity’s total asset value as of December 31 for each calendar year. The framework is designed to allocate a greater share of costs to entities with larger asset bases, while limiting volatility and administrative burden for smaller participants and new entrants.
Violations
The proposed Regulations would designate which provisions of the Act and Regulations may be treated as violations, subject to administrative monetary penalties determined by the Bank of Canada, and that do not need to be treated as offences. The majority of the provisions would relate to the common rules or obligations that all participating entities must adhere to as part of their participation in the framework, such as those related to consent, authentication, disclosure of information, and reporting.
In accordance with the Act, the maximum penalty for a violation is $1,000,000 if the violation is committed by an individual and $10,000,000 if committed by a participating entity or ATPSP. The Act does not establish a minimum penalty for violations and the precise penalty issued by the Bank of Canada is left to its discretion as the supervisor.
Regulatory development
Consultation
The development of Canada’s consumer-driven banking framework, including the proposed Regulations, has benefited from extensive consultation with hundreds of industry stakeholders, including banks, credit unions, fintechs, and industry associations, as well as academics, civil society organizations, not-for-profit organizations, industry experts, federal government departments and agencies, provinces and territories, and other jurisdictions, including the United Kingdom and Australia.
Engagement on this topic began with Budget 2018, when the Government announced a review into the merits of open banking. As a first step, the Minister of Finance appointed the Advisory Committee on Open Banking to guide the review with support from a secretariat within the Department of Finance. The Advisory Committee was tasked with considering whether open banking would provide meaningful benefits to Canadians and delivering a report assessing the potential merits of open banking for Canada, with the highest regard for consumer privacy, security, and financial stability.
The Department of Finance and the Advisory Committee released its first consultation paper in 2019, A Review into the Merits of Open Banking, resulting in over 120 written submissions from industry stakeholders, including banks, fintechs, industry associations and federal government departments and agencies. Of the 120 submissions, those whose authors consented to make public are available online in the Submissions for Consultation Paper on Open Banking.
Throughout the course of its review, the Advisory Committee and Department of Finance engaged hundreds of stakeholders through public roundtables and bilaterally. A broad range of stakeholders were consulted as part of this process, from traditional financial sector stakeholders to Canadian consumers and civil society organizations representing small business owners, Canadians, and their families. Multi-stakeholder roundtables, which each engaged between 50 and 150 stakeholders, were held in Vancouver, Toronto, and Montreal. The Department of Finance and the Advisory Committee engaged international policy-makers to understand best practices in first-mover jurisdictions including Singapore, the United Kingdom, the European Union, and Australia. In support of the review, the Department of Finance also undertook qualitative public opinion research, the results of which can be found on the Library and Archives Canada website.
In January 2020, the Advisory Committee released a report entitled Consumer-directed finance: the future of financial services summarizing what it heard from stakeholders and learned from its examination of consumer-directed finance in other jurisdictions, formal recommendations, and considerations for next steps.
In 2020, the Advisory Committee undertook a second phase of consultation to identify implementation considerations, examining issues such as governance, consumer control of personal data, privacy, and security. This consultation included multiple workshops, each including between 24 and 48 industry stakeholders, such as banks, credit unions, fintechs, industry associations, consumer groups, provinces and territories, dealing with core issues, such as scope, governance, and accreditation. Canadians and stakeholders were again invited to share feedback, including through a dedicated email inbox, which resulted in 33 formal written submissions from industry stakeholders, including fintechs, banks and industry associations. A second round of quantitative and qualitative public opinion research was also undertaken. This second phase of consultation resulted in the Committee’s 2021 Final Report (PDF), which included 34 recommendations for a made-in-Canada approach to open banking, including to appoint an open banking Lead to develop the common rules, accreditation criteria, and to set technical standards.
Based on the Committee’s recommendation, Abraham Tachjian was appointed by the Minister of Tourism and Associate Minister of Finance in 2022 as the Open Banking Lead tasked with engaging industry, regulators, and consumer representatives. The Lead established four working groups on privacy, security, accreditation and liability, as well as a Steering Committee. This work resulted in more than 25 working group meetings and more than 200 stakeholder engagements between 2022 and 2023. Consumer groups were invited to participate and received funding to provide feedback to the Department of Finance on how to proceed with implementation using a consumer-first approach. The discussion guide and outcomes of each meeting are posted on the Department of Finance website and were used in the development of the Lead’s final recommendations to the Minister. Following the introduction of the first part of the Act in 2024, which included elements related to scope, governance and technical standards, the Department of Finance undertook five weeks of stakeholder consultation on the remaining elements, which culminated in a sworn-in review for industry, provinces (both departments and agencies), and consumer groups.
More than one hundred one-on-one discussions with stakeholders, including banks, credit unions, other federally and provincially regulated financial institutions, fintechs, and their industry associations, as well as consumer groups, and domestic and international subject matter experts, have also been ongoing throughout the regulatory development process. These one-on-one discussions have informed the government’s understanding of current industry practices, such as the API minimum service level requirements, and the impact of the regulatory requirements.
The Department of Finance has engaged extensively with provincial and territorial governments and regulatory bodies throughout the legislative and regulatory development process. For example, provincial governments and regulators were involved in the Open Banking Lead’s working groups. The Department of Finance has also met regularly with provincial and territorial governments and regulators, including bilateral discussions at the Deputy Minister level, and via existing multilateral fora. These engagements have helped inform the development of the proposed Regulations, particularly in areas where provinces oversee provincial financial institutions, including security, privacy (such as consumer consent and authentication), liability, complaints handling, and consumer protection.
The proposed Regulations were also developed in consultation with other federal government departments and agencies with roles and mandates relevant to the consumer-driven banking framework. This incudes the Bank of Canada as the supervisory authority responsible for implementing and overseeing the framework; OSFI as the supervisory authority responsible for the Bank Act; the Financial Consumer Agency of Canada as the supervisory authority responsible for the Bank Act’s Financial Consumer Protection Framework; Innovation, Science and Economic Development Canada (ISED) to ensure alignment with PIPEDA and any future successor legislation; the Competition Bureau as the independent law enforcement agency that protects and promotes competition law in Canada; and the Canadian Security Intelligence Service, the Communications Security Establishment, Public Safety Canada, and the Royal Canadian Mounted Police, on the inclusion and design of the framework’s national security safeguards. In 2024 senior executive and working-level committees were established to consult on the development of the remaining elements of the consumer-driven banking framework. This consultation ran in conjunction with industry and other stakeholder engagement and included the aforementioned departments and agencies.
The Department of Finance also consulted the Office of the Privacy Commissioner, an Office of Parliament, as an authority on privacy law and the protection of personal information.
Throughout this consultation process, concerns raised by individual stakeholders and industry groups varied by group. While views diverged in some places, there was general agreement that the framework should establish a process and criteria for regulation, and should establish common rules that protect consumers, while ensuring that all entities are equally subject to the same rules and requirements.
Incumbent financial institutions raised that forthcoming regulations should provide a secure foundation for consumer financial data sharing that apportioned liability appropriately (with respect to consent and authentication) and prohibited unsecure means of data sharing. They also noted that accreditation criteria for all prospective participating entities should be sufficiently robust to address operational and cybersecurity risks. Incumbent financial institutions also recommended that exceptions to the requirement to share data be defined broadly, to allow entities greater flexibility to stop sharing when a potential risk arises.
Feedback from incumbent financial institutions was considered in the development of the proposed Regulations. While the legislation clearly articulates the liability structure and respective responsibilities of participating entities, the proposed Regulations provide greater detail regarding these responsibilities to ensure there is no discrepancy about which party is responsible for which activity (e.g. consent and authentication). The proposed Regulations also adopt an approach to accreditation criteria that aims to address all of the public policy objectives of the framework, namely competition and innovation, security and stability and consumer protection, in a balanced manner. In so doing, the proposed Regulations ensure that risks are sufficiently addressed without creating unnecessary regulatory burden for new entrants.
The proposed Regulations do not broadly define the circumstances under which a participating entity is exempt from the requirement to share. Broad exemptions would be inconsistent with Canadians’ right to data portability, as enshrined in amendments to PIPEDA, which received Royal Assent in March 2026, and could lead to confusion or disputes about which circumstances applied. As a result, the proposed Regulations articulate circumstances (e.g. an account has been suspended) which align with those applied in open banking frameworks in other jurisdictions, adapted for the Canadian context. The included circumstances are based on extensive discussions with a broad cross-section of stakeholders including industry and regulators in other jurisdictions with open banking frameworks.
Credit unions and other provincially regulated financial institutions wanted to ensure that there were no barriers to provincial entities’ participation and to avoid duplication in regulatory burden associated with the accreditation process and the application of common rules. These proposed accreditation criteria for provincially regulated financial institutions address these concerns by relying on existing security protocols applied by a provincial regulator, and limiting accreditation criteria to areas not already addressed by a provincial regime, such as national security and technical standards. This approach ensures robust regulatory controls while seeking to minimize potential overlap or duplication of requirements for participating entities overseen by provincial regulators.
Fintechs and smaller entities wanted to ensure that the regulations did not stifle innovation or create substantial barriers to entry for new and smaller entities, that the regulatory burden was proportionate and scope was commensurate with existing data-sharing services. In response, the proposed Regulations related to the accreditation processes and criteria, as well as those related to participating entities’ responsibilities, reflect these concerns by striking a balance between the need for security and consumer protection and the need to be proportionate, risk-based and enable innovation and competition. They ensure that entities’ responsibilities at each part of the data sharing process are clearly articulated so that the liability to the consumer flows with the data and rests with the party at fault. The accreditation criteria proposed in the Regulations are reflective of feedback from federally and provincially regulated financial institutions that the path to entry should recognize and not duplicate existing requirements that address prudential and other forms of risk.
Provincial governments wanted to ensure that the framework, and related regulations in so far as they related to areas of shared responsibility, were not misaligned with provincial rules and that any overlap was minimized. These concerns were reflected in both the legislation and the proposed Regulations, which are limited to only the act of sharing the data and not the underlying financial products and services, which are overseen through existing federal and provincial rules.
In keeping with the Government’s commitment to robust consultation on the development of the Canadian consumer-driven banking framework, the proposed Regulations are subject to an extended prepublication period of 60 days to provide stakeholders with adequate time to provide meaningful feedback on the proposed Regulations. This extended period would provide the broad range of diverse stakeholders impacted by these novel requirements, including financial sector stakeholders, industry associations, provincial and territorial governments, and consumer groups, sufficient time to interpret and comment on the regulations. This will, in turn, ensure that the government can fully consider their unique perspectives in the finalization of the regulations and support efficient and timely implementation by all impacted stakeholders upon coming into force.
Indigenous engagement, consultation and modern treaty obligations
The proposed regulations are not expected to have any differential impacts on Indigenous peoples or implications for modern treaties, as per the Government of Canada’s obligations in relation to rights protected by section 35 of the Constitution Act, 1982, modern treaties, and international human rights obligations.
Instrument choice
The development of Canada’s consumer-driven banking framework has benefited from close observation of models employed in other jurisdictions. International approaches to consumer-driven banking vary between those that are industry-led and those that are government-led. Lessons learned from other jurisdictions demonstrate that government involvement in the establishment of common rules, technical standards, accreditation requirements, and oversight functions is critical to the success of the system, both in terms of creating a fair ecosystem for participants and ensuring consumer trust. To date, all successful consumer-driven baking frameworks have been government-led, with strong governance frameworks informed by legislation and regulation, such as those implemented in Australia, New Zealand, Brazil, India, the European Union, and the United Kingdom. Jurisdictions that have adopted purely industry-led models have largely abandoned these approaches, owing to fragmentation and poor consumer outcomes.
Domestic consultations and policy development have resulted in similar conclusions. Notably, Canada’s consumer-driven banking framework was informed by the work of the Open Banking Lead appointed in 2022, including recommendations that a Canadian framework be enshrined in legislation and supporting regulations. Building on the lessons learned from international experiences and domestic policy advice from subject matter experts, Canada has opted for a government-led model in which rules are set through legislation and regulation and authority to oversee the system is allocated to a government entity, in this case, the Bank of Canada. Enshrining the framework within legislation and regulation ensures that the system can meet key public policy objectives, including competition, innovation, utility to consumers, consumer protection and the ability to expand the framework to scope in other sectors in the future, all of which will maximize the benefits to the Canadian economy.
Regulatory analysis
Benefits and costs
The impacts of the proposed Regulations have been assessed in accordance with the Treasury Board of Canada Secretariat (TBS) Policy on Cost-Benefit Analysis and Canadian Cost-Benefit Analysis Guide. The benefits and costs associated with the proposed Regulations are determined by comparing the baseline scenario against the regulatory scenario. The baseline scenario depicts what is likely to happen in the future if the proposed Regulations are not implemented. The regulatory scenario describes the changes expected to occur due to the proposed Regulations. The impacts described are incremental differences between these two scenarios that are anticipated and thus attributable to the proposed Regulations.
The total cost of the proposed Regulations is $457.7 million over ten years in present value (TPV) [or $65.27 million annualized] in 2025 dollars. The TPV of benefits of the proposed Regulations is $13.2 billion over ten years (or $1.9 billion annualized) in 2025 dollars. Unless otherwise stated, all monetary values are expressed in 2025 dollars, discounted to 2027 using a discount rate of 7% over a 10-year period (2027 to 2036). There are additional qualitative benefits of the proposed Regulations, which are described below due to the difficulty associated with quantifying them.
A full cost-benefit report with more details on the methodology and assumptions employed is available upon request.
Baseline and regulatory scenarios
The baseline scenario assumes that the Consumer-Driven Banking Act has been implemented. As a result, the cost and benefit estimates presented in this analysis capture only the incremental impacts associated with the proposed Regulations relative to the legislative baseline. Costs and benefits that stakeholders would reasonably incur to comply with the Act itself are not included in this analysis.
Therefore, the costs described should be interpreted as the incremental administrative and compliance costs resulting from the proposed regulatory provisions, rather than the total costs of implementing the consumer-driven banking framework as a whole.
Benefits
A series of value-transfer scenarios based on United Kingdom open banking evidence presented in the report “Unlocking the Everyday: The Value, Growth and Opportunity of Open Banking in the UK (PDF)” were developed to estimate potential benefits in specific, well-defined use cases that could be enabled by the proposed Regulations. The United Kingdom was selected given its position as a global leader in open banking, and because it has consistently served as a benchmark for best practices and lessons learned for the development of the Canadian framework.
Across all use cases, it is assumed that the value transfer from the United Kingdom to Canada is appropriate after adjusting for inflation (1.045 from 2023 to 2025 and 1.021 from 2024 to 2025, where applicable) and the exchange rate (1.678 in 2023, 1.75 in 2024, and 1.842 in 2025, where applicable). All population-based calculations use the population aged 15 and over, with United Kingdom per-person benefit estimates applied to relevant Canadian populations (33.4 million in Canada and 57.5 million in the United Kingdom in 2024). Benefits are then estimated using a 27% participation rate, equivalent to approximately 9 million Canadians (27% of 33.4 million) adopting consumer-driven banking at the outset.
These use cases are illustrative and non-exhaustive and are intended to provide conservative estimates of benefits in areas where monetization is feasible. As the framework matures, a broader range of innovative use cases is expected to emerge, unlocking additional benefits not reflected in the present value estimates.
Enhanced affordability assessments for lending
For many people, credit is refused due to reliance on traditional credit scores that may not capture broader financial behaviour. Consumer-driven banking enabled tools can use financial transaction data to identify spending patterns and borrowing repayment habits that may prove that more people are a lower credit risk compared to information available in a typical credit report, helping more people gain access to credit, including at lower interest rates.
Nine million Canadians are credit unserved or underserved (TransUnion, 2022). The estimate assumes that the untapped credit demand, relative to this population, is comparable between the United Kingdom and Canada. The United Kingdom analysis assumes that incorporating transaction data from open banking into affordability assessments can expand lending by 14%. Therefore, a 14% increase in lending is applied to both the value of untapped credit demand and the credit unserved or underserved population to estimate the increase in credit extended and the number of individuals gaining access to credit. This results in a per-person benefit of $212.64, applied to 14% of the expected nine million users of consumer-driven banking who could gain access to credit.
Streamlined small and medium-sized enterprise (SME) account administration
Consumer-driven banking enabled tools can streamline administrative tasks for SMEs by allowing secure, real-time access to financial data across multiple accounts and financial institutions. Transaction categorization and cash flow tracking can reduce the need for manual data entry and simplify bookkeeping, tax preparation, and financial reporting processes. For SME owners, who often manage administrative functions alongside core business operations, these efficiencies translate into meaningful time savings that can be reallocated towards higher-value activities.
Time savings from using consumer-driven banking are assumed to be 52 hours per year from the United Kingdom study, valued at $35.60 per hour. SME participation is estimated by applying the same 27% participation rate used for consumer uptake of consumer-driven banking to the approximately 1.09 million Canadian SMEs, resulting in 293 731 SMEs that could benefit from reduced administrative burdens.
Optimization of savings accounts
Consumer-driven banking enabled tools can use chequing account transaction data to identify where money is going and how much is typically available each month for potential savings. With this information, the tool can provide advice and prompt consumers to direct their funds from a chequing account to a savings account with a higher return.
Higher returns on savings are estimated to generate a benefit of $57.78 per person annually. The estimate uses the assumption from the United Kingdom that 20% of the population holds account balances above a threshold and could shift funds into an easy-access savings account with a return of 2.11%, which is applied to the expected nine million users of consumer-driven banking. This could lead to more money invested in savings accounts and may result in overall lower interest rates for these types of accounts; however, this is not accounted for in these estimates.
Reducing the cost of recurring services
Many consumers fail to seek better deals at the end of a contract, often due to a lack of awareness or perceived complexity, which leads to consumers paying higher rates when competitive alternatives may exist. Consumer-driven banking enabled tools can address this issue by using transaction data to identify the cost of your services while scanning the market to identify opportunities for savings.
Mobile
The per-person annual savings from switching mobile plans is estimated at $119.65, based on the United Kingdom’s switching savings. The share of Canadians with a mobile phone, 95%, and the United Kingdom-derived assumption that 20% of consumers are on outdated plans imply that 19% of consumers would benefit (Media Technology Monitor, 2025). This proportion is applied to the expected nine million users of consumer-driven banking.
Broadband
Annual savings from switching broadband services are estimated at $187.56 per household, based on United Kingdom switching savings. This is converted to a per-person value of $78.15 using an average household size of 2.4 persons. The share of Canadians living in broadband-connected households, 96.4%, and the United Kingdom-derived proportion of households that are out of contract (43%) imply that approximately 41.5% of users would benefit, which is applied to the expected nine million users of consumer-driven banking (Canadian Radio-television and Telecommunications Commission, 2024).
Identification of unused subscriptions
The increase in subscription-based services has led to a growing number of consumers paying for services they no longer use or have forgotten to cancel, resulting in avoidable recurring expenses. Consumer-driven banking enabled tools can address this issue by aggregating a consumer’s financial transaction data across accounts to identify recurring subscription payments and flag potentially unneeded services.
The United Kingdom analysis uses reported estimates of the current total value of unused or forgotten subscriptions and assumes that, once consumer-driven banking tools identify all recurring subscription payments and allow users to flag those that are forgotten or unused, these subscriptions are cancelled, resulting in a 100% reduction in unused subscription spending. This estimate is converted into a per-person annual savings of $28.42 for consumer-driven banking users who have unused subscriptions. This is applied to the 66% of Canadians with forgotten subscriptions, within the 85% who pay for at least one subscription (Scotiabank, 2025; CRR Research, 2022), among the expected nine million consumer-driven banking users.
Costs
The direct costs associated with the proposed Regulations are expected to be borne by federally regulated financial institutions, provincially regulated financial institutions, payment service providers, other entities (fintechs, etc.), third-party service providers, mandated banks, the Bank of Canada, the external complaints body, and the technical standards body.
Some of the costs would occur as upfront, one-time costs in the first year of the framework, such as accreditation fees or capital costs related to building the information technology (IT) infrastructure. Other costs, such as labour costs related to quarterly or annual reports, are ongoing and would be incurred over the 10-year time horizon.
Accreditation and fees
It is estimated that businesses seeking entry into the framework would incur administrative and compliance costs related to accreditation and ongoing supervisory oversight. In addition to labour costs, applicants would incur a one-time accreditation fee per application of $2,500 adjusted to inflation and rounded to the nearest $100 on a yearly basis.
Participating entities, ATPSPs, and the external complaints body would also incur ongoing annual assessment fees. The external complaints body would be subject to a fixed annual fee of $50,000, and ATPSPs subject to a fixed annual fee of $10,000. For participating entities, the annual assessment fee is composed of a base fee and a variable fee. The base fee payable by participating entities is determined according to the asset tier corresponding to the entity’s total asset value, ranging from $10,000 up to $150,000. The variable fee is calculated by applying the applicable Variable Fee Distribution percentage to the pool of remaining recoverable costs that have been applied, distributed equally between entities within that tier. The percentage assigned to each asset tier determines the proportion of the remaining recoverable costs to be allocated equally between entities within that tier. However, any estimate of the value of remaining recoverable costs before the framework is in operation would be highly speculative at this time, so this variable fee has not been included in the analysis.
Routine reporting, notices, signage, and record keeping
It is estimated that regulated entities would incur recurring administrative costs associated with routine reporting, notices, signage updates, and record-keeping obligations. Certain notice-of-change obligations are estimated to require 30 minutes per filing, while annual reporting obligations are estimated to require three hours per report. Minor disclosure-related obligations, such as updating required signage where applicable, are estimated to require one hour annually per participating entity. Record-keeping obligations may also require one-time IT build costs of approximately $5,000 for some participating entities and ATPSPs, in addition to ongoing labour to maintain records. No material incremental record-keeping cost is assumed for mandated banks, federally regulated financial institutions, and provincially regulated financial institutions where comparable systems and processes are already expected to exist.
Operational requirements
Participating entities would be subject to operational requirements and would likely incur both upfront capital costs and ongoing compliance labour costs related to authentication, verification, authorization, minimum service-level standards, and right of refusal. Upfront capital costs are associated with establishing or adapting technical functionality, including API capabilities, where required. These one-time costs are estimated at $10,000 for mandated banks, federally regulated financial institutions, and provincially regulated financial institutions, and $5,000 for PSPs and other entities where implementation is expected to be less complex.
Ongoing labour costs would also be incurred to support authentication, verification, authorization, minimum service-level requirements, and the administration of refusal decisions in prescribed circumstances. These ongoing costs are estimated at approximately three months equivalent annually for mandated banks and financial institutions, and one month annually for PSPs and other entities reflecting their lower expected implementation complexity.
Security compliance and incident reporting
It is estimated that participating entities would incur upfront and ongoing compliance costs to establish and maintain security safeguards, as well as additional costs when reportable incidents occur. For PSPs, it is assumed that 75% already maintain sufficient security infrastructure, such that only 25% would incur upfront implementation costs. For these entities, and for other entities that do not already have sufficient measures in place, upfront implementation costs are estimated at one quarter of a full-time equivalent. Ongoing compliance with security requirements is estimated to require approximately one week of labour annually for affected entities. Where a reportable incident occurs, additional labour would be required to investigate the incident and complete reporting obligations. The cost of incident investigation and reporting is estimated at 100 hours per incident. In the central analysis, such incidents are assumed to affect 2% of entities per year.
Bank of Canada registry
It is estimated that the Bank of Canada would incur upfront and ongoing costs to establish and maintain core implementation infrastructure to support the operation of the framework. This includes a one-time capital cost to build an IT system linked to a public registry in order to facilitate real-time registry updates to participating entities. In addition, ongoing labour is required to maintain and update the registry and supporting IT infrastructure.
Clarificatory provisions and qualitative consumer impacts
For some provisions, no material incremental quantitative cost is estimated because the proposed Regulations would not incur a cost, as they are intended to clarify an existing underlying obligation from the Act. In these cases, the proposed Regulations provide additional specificity, but are not expected to generate a distinct incremental labour or capital cost.
Cost-benefit statement
- Number of years: 10 (2027 to 2036)
- Price year: 2025
- Present value base year: 2027
- Discount rate: 7%
| Impacted stakeholder | Description of benefit | First year | Final year | Total (PV) | Annualized value |
|---|---|---|---|---|---|
| Canadians | Enhanced affordability assessments for lending | $273,282,386 | $326,597,748 | $2,078,722,737 | $295,963,352 |
| Canadians/SMEs | Streamlined SME account administration | $701,003,160 | $837,763,667 | $5,332,181,230 | $759,182,648 |
| Canadians | Optimization of savings accounts | $106,090,579 | $126,788,063 | $806,978,097 | $114,895,526 |
| Reducing the cost of recurring services | $502,840,409 | $600,940,836 | $3,824,856,066 | $544,573,455 | |
| Identification of unused subscriptions | $146,367,195 | $174,922,347 | $1,113,342,216 | $158,514,884 | |
| All stakeholders | Total benefits | $1,729,583,729 | $2,067,012,661 | $13,156,080,347 | $1,873,129,866 |
| Impacted stakeholder | Description of cost | Base year | Final year | Total (PV) | Annualized value |
|---|---|---|---|---|---|
| Government, agencies, and Crown corporations | Costs incurred by Bank of Canada | $1,110,576 | $54,103 | $1,436,472 | $204,521 |
| Industry | Costs incurred by FRFIs, PRFIs, mandated banks, other entities, and third-party service providers | $47,972,765 | $72,678,784 | $455,867,781 | $64,905,316 |
| Framework bodies | Costs incurred by the external complaints body and the technical standards body | $52,172 | $52,172 | $366,434 | $52,172 |
| All stakeholders | Total costs | $49,135,513 | $72,785,059 | $457,670,687 | $65,162,010 |
| Impacts | Base year | Final year | Total (PV) | Annualized value |
|---|---|---|---|---|
| Total benefits | $1,729,583,729 | $2,067,012,661 | $13,156,080,347 | $1,873,129,866 |
| Total costs | $49,135,513 | $72,785,059 | $457,670,687 | $65,162,010 |
| NET IMPACT | $1,680,448,216 | $1,994,227,602 | $12,698,409,660 | $1,807,967,856 |
Quantified (non-monetized) and qualitative impacts
Positive impacts
- Consumers would benefit from improved visibility over their financial position across financial accounts, products, and institutions, which may support better financial decision-making and easier comparison of products and services.
Negative impacts
- Consumers may incur marginal indirect costs through slightly higher prices for some financial services, to the extent that participating entities pass through a portion of administrative and compliance costs on to their clients.
Sensitivity analysis and distributional analysis summary
The impacts of the proposed Regulations are expected to fall primarily on institutional and business participants rather than on consumers. Direct compliance and administrative costs would be concentrated among entities that are mandated to participate in, opt into, oversee, or support the framework, including costs related to implementation, labour, accreditation, reporting, record keeping, security compliance, service standards, and incident response. These impacts are expected to be proportionately greater for small businesses, since many compliance costs are fixed and therefore represent a larger burden relative to firm size and resources. Based on current estimates, approximately 578 of the 680 affected businesses are small businesses, and the average small business is expected to incur an annualized cost of $89,133. Although large institutions, including mandated banks, may face higher absolute costs because of their scale and system complexity, they are generally better positioned to absorb these costs. No distinct differential impacts have been identified for Indigenous groups, demographic subgroups, or regions. Consumers are not expected to face direct costs, consistent with the Act’s prohibition on charging for data sharing, although limited indirect costs could arise if some business costs are passed on through the pricing of financial services.
Sensitivity analysis indicates that the main cost drivers are the number of participating entities accredited in the first year and the discount rate used in the cost-benefit analysis. The central scenario assumes a 25% first-year opt-in rate, equivalent to approximately 680 affected businesses, while the low and high scenarios assume opt-in rates of 15% and 35%, respectively. Under these scenarios, TPV costs range from $425.9 million to $486.3 million, and annualized costs range from $60.6 million to $69.2 million. While total costs increase as more entities participate, the average annualized cost per entity declines as fixed costs are spread across a larger number of participants. The analysis assumes opt-in rates rise by 15 percentage points annually until reaching a steady-state cap of 80%. Sensitivity testing on the discount rate shows that TPV costs range from $532.2 million at 4% to $397.7 million at 10%, compared with $457.7 million under the central 7% rate.
Small business lens
Analysis under the small business lens concluded that the proposed Regulations would impact small businesses. It is estimated that approximately 680 businesses would be impacted by these proposed Regulations, with 86% being small businesses, resulting in a total of 578 small businesses impacted.
It is expected that participating entities or ATPSPs that are small businesses would incur administrative and compliance costs. These costs stem from the provision of documents to the Bank of Canada under various regulatory requirements, costs to implement and demonstrate compliance with the technical standard and security measures, as well as additional human resource costs and IT system changes that would be required to support the implementation of these regulatory provisions.
Alternative compliance options for small businesses would not be possible because the proposed Regulations are intended to create the same privacy, liability, and security safeguards for all consumers consenting to their data being shared across the framework, regardless of the size of the participating entity or ATPSP involved in the data sharing process.
However, under the proposed Regulations, the Bank of Canada would establish a tiered assessment fee structure for participating entities based on the value of their total assets, such that smaller businesses would pay lower annual assessment fees than larger entities.
Small business lens summary
- Number of small businesses impacted: 578
- Number of years: 10 (2027 to 2036)
- Price year: 2025
- Present value base year: 2027
- Discount rate: 7%
| Administrative or compliance | Description of cost | Present value | Annualized value |
|---|---|---|---|
| Administrative | Total administrative costs incurred by small businesses | $2,695,743 | $383,813 |
| Compliance | Total compliance costs incurred by small businesses | $359,261,686 | $51,150,782 |
| Total | Total costs | $377,714,728 | $53,778,080 |
| Amount | Present value | Annualized value |
|---|---|---|
Net impact on all impacted small businesses |
$361,957,429 | $51,534,595 |
Average net impact on each impacted small business |
$626,036 | $89,133 |
One-for-one rule
The proposed Regulations are a new regulatory title that introduces new administrative costs to businesses.
Entities that are mandated or opt-in to participate in the consumer-driven banking framework will experience new administrative costs associated with the proposed Regulations. This burden stems from new reporting and information requirements, as well as human resources and IT system costs to support the implementation of the proposed Regulations.
Using assumptions and data presented above and the methodology developed in the Red Tape Reduction Regulations, which requires results to be reported in 2012 CAD and discounted to a 2012 base year, it is estimated that the regulated community will assume total administrative costs of $849,651 (present value) over 10 years, or $120,971 annualized for all participating entities and ATPSPs. This equates to $1,249 (present value) per business over 10 years or $178 annualized per business.
Regulatory cooperation and alignment
Worldwide, the development of open banking frameworks has been uneven, shaped by diverse regulatory models, technical standards, and institutional priorities. The Department of Finance has examined open banking systems in other jurisdictions, learning from their implementation experiences, to help develop a made-in-Canada consumer-driven banking framework. The United Kingdom and Australia are two key jurisdictions where the Department of Finance is attentive to lessons learned due to comparable regimes and demonstrated success, while also monitoring developments in other jurisdictions, like Brazil, the United States, and countries belonging to the European Union. Key elements of the proposed Regulations, such as the accreditation and reporting requirements, align with many of the requirements found in successful open banking regimes, such as the framework implemented in Australia.
Domestically, the Act accounts for provincial and territorial regulatory cooperation and alignment by enabling the Minister of Finance to designate a provincial or territorial authority to supervise certain provisions on an identified provincial financial institution or class of provincial financial institutions when certain provisions are met. This will facilitate oversight of provincial entities while respecting their jurisdiction. The Act also authorizes the Minister of Finance to issue an order that exempts a participating entity or class of participating entities from the legislative obligation to be a member of the federally designated external complaints body if they are a member of a provincial equivalent, for example, a provincially designated or regulated complaints dispute body. The Act further establishes a federal, provincial and territorial advisory committee that is co-chaired by the federal government and one rotating provincial co-chair. This committee will serve as the forum to discuss future legislative and regulatory developments, operational challenges, and priorities for the consumer-driven banking framework.
All participating entities will be subject to the consumer-driven banking framework and Bank of Canada supervision, unless otherwise provided, as described above. To facilitate the participation of provincially regulated financial institutions, the governance model is structured in a manner that allows provincial credit unions and crown corporations that offer deposit-taking services or provincial insurance companies to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.
International obligations
The proposal is not linked to any international agreements or obligations.
Effects on the environment
In accordance with the Cabinet Directive on the Environmental Assessment of Policy, Plan and Program Proposals, a preliminary scan concluded that this proposal is not expected to result in any direct and significant environmental impacts, including Canada’s emission targets. Therefore, a strategic environmental assessment is not required.
Gender-based analysis plus
A gender-based analysis plus (GBA+) assessment was undertaken for the proposed Regulations. Overall, the proposed Regulations are expected to enable data sharing to support consumers and small businesses in exercising a data portability right in a safe and secure ecosystem. Canadians would have the option of secure access to innovative financial services and products that better meet their needs, the ability to provide specific and revokable consent, improved consumer protections and reduced exposure to liability, privacy, and security risks.
There are sources that suggest vulnerable consumers, such as those with lower income, may benefit from real-time access to their whole financial picture (American Banker). Similarly, consumers with limited credit profiles such as new and younger Canadians may benefit from the ability to use their transaction history to build credit. Services that, for example, enable renters to use evidence of on-time rental payments to demonstrate credit worthiness may facilitate access to home ownership and reduced borrowing costs. Younger generations may also be more likely to make use of digital financial services and therefore reap greater benefits from consumer-driven banking.
It is unclear that differences along age and income lines will produce benefits that are predominately stronger than the rest of the population at large. Given that all Canadians are expected to benefit from the proposed Regulations, no specific measures to address or mitigate GBA+ impacts are required.
Implementation, compliance and enforcement, and service standards
Implementation
The proposed Regulations would come into force when the relevant provisions of the Act come into force, as fixed by orders of the Governor in Council. The proposed Regulations would come into force following a staggered approach, starting with the accreditation requirements, with the requirements related to common rules and assessment fees following at later dates.
Elements of the framework related to “in scope data” (e.g. accounts) would also be phased in with staggered coming-into-force dates in accordance with the complexity of account type, beginning with deposit and payment accounts, then moving to lending accounts, registered accounts, and then non-registered accounts.
While the final decision on the precise timing of the staggered coming-into-force dates would be taken following the Canada Gazette, Part I, consultations, the full suite of proposed Regulations is intended to be in force within one year of final publication in the Canada Gazette, Part II.
Ministerial Orders to designate the technical standards body and external complaints body would be issued and published in the Canada Gazette in advance of the coming into force of the proposed Regulations to fully operationalize the framework.
Authorities for the Minister to designate a provincial or territorial authority to supervise certain legislative provisions are not mandatory for the framework to come into force or to be implemented. The provision is an enabling authority that provinces can request be exercised.
The Bank of Canada is a Crown corporation that operates independently and at arm’s length from the federal government. Once the proposed Regulations are published in the Canada Gazette, Part II, the Bank of Canada will issue guidelines for consultation on specific topics related to the Act to further clarify its supervisory expectations. These documents will be published on the Bank of Canada website in advance of the proposed Regulations coming into force and will explain how the Bank of Canada interprets the Act and provide transparency around the Bank of Canada’s supervisory role.
Compliance and enforcement
Under the Act and proposed Regulations, the Bank of Canada will be responsible for supervising participating entities and ATPSPs, promoting compliance among participating entities of their obligations under the Act and proposed Regulations, and monitoring and evaluating trends related to Canada’s consumer-driven banking framework.
All participating entities will be subject to the consumer-driven banking framework and Bank of Canada supervision. To facilitate the participation of provincially regulated financial institutions, the governance model will be structured to allow provincial credit unions and crown corporations that offer deposit-taking services and provincial insurance companies to “opt-in” to the framework. Provinces and territories retain the authority to impose their own requirements on entities subject to their jurisdiction and participating entities will continue to be required to follow all applicable federal and provincial frameworks.
In addition, the Act authorizes the Minister of Finance, upon request from a provincial equivalent, to designate the supervision of certain legislative provisions to a provincial authority when certain criteria are met. The provincial authority will be responsible for the supervision of the Act’s obligations, but the enforcement of those provisions will rest with the Bank of Canada. It is anticipated that clear information sharing agreements will be in place prior to any such designation to ensure that effective collaboration can occur between the federal and provincial supervisors. The collaborative nature of the framework is further enhanced by the establishment of a federal, provincial and territorial advisory committee, which will provide advice to all relevant federal and provincial ministers regarding the implementation and evolution of the framework.
The Act also provides the Minister of Finance with the authority to address risks related to national security that could be posed by participating entities and ATPSPs. This includes the ability to refuse the accreditation of entities and third-party service providers seeking to enter the consumer-driven banking framework, revoking accreditation status, ordering undertakings or conditions, as well as issuing national security orders for a participating entity to take or refrain from any action. The Minister will be supported by the Department of Finance, as well as Canada’s security and intelligence community (government authorities) providing information (intelligence and analysis) in accordance with their respective mandates.
The legislation provides the Bank of Canada with a range of enforcement tools, such as the ability to suspend or revoke accreditation, issue undertakings, terms or conditions, or impose administrative monetary penalties on entities that violate the Act.
Service standards
To ensure clarity and consistency across all framework participants, the timelines for accreditation and national security reviews are set out in the proposed Regulations. Further information on these timelines can be found in the “Description” section of this Regulatory Impact Analysis Statement.
Contact
KĂŻrsten Fraser
Director, Financial Services Innovation
Financial Services Division
Financial Sector Policy Branch
Department of Finance Canada
90 Elgin Street
Ottawa, Ontario
K1A 0G5
Email: obbo@fin.gc.ca
PROPOSED REGULATORY TEXT
Notice is given that the Governor in Council proposes to make the annexed Consumer-Driven Banking Regulations under sections 155 and 178 of the Consumer-Driven Banking Act footnote a.
Interested persons may make representations concerning the proposed Regulations within 60 days after the date of publication of this notice. They are strongly encouraged to use the online commenting feature that is available on the Canada Gazette website. However, if they use email, mail or any other means, the representations should cite the Canada Gazette, Part I, and the date of publication of this notice, and be sent to KĂŻrsten Fraser, Director, Financial Services Division, Financial Sector Policy Branch, Department of Finance Canada, 90 Elgin Street, Ottawa, Ontario K1A 0G5 (email: obbo@fin.gc.ca).
Please note that as part of the publication process, all representations, including attachments, will be published on the Canada Gazette website, subject to its terms of use relating to the provision of comments.
Ottawa, June 19, 2026
Janna Rinaldi
Assistant Clerk of the Privy Council
Consumer-Driven Banking Regulations
Definition
Definition of Act
1 In these Regulations, Act means the Consumer-Driven Banking Act.
Application
Data
2 For the purpose of subsection 10(1) of the Act, the data in respect of which the Act applies includes the following data relating to the products and services referred to in that subsection:
- (a) data pertaining to the identity of consumers of the products or services;
- (b) account numbers, branch numbers, transit numbers and other identifiers pertaining to the products or services;
- (c) the terms under which the products or services are provided, including in relation to fees, interest rates and authorizations;
- (d) current or past balances or amounts owing;
- (e) data pertaining to completed, pending or pre-authorized transactions; and
- (f) data respecting the products or services that are available or offered to consumers, including the terms under which they are available or offered.
Accreditation
Accreditation as a Participating Entity
Application — federal or provincial financial institution
3 (1) An application referred to in subsection 15(1) of the Act must contain
- (a) the applicant’s legal name and any trade name under which it intends to provide services in accordance with the Act;
- (b) the date and jurisdiction of the applicant’s incorporation or other formation and, in the case of a corporation, its incorporation number;
- (c) the applicant’s primary civic and mailing addresses;
- (d) the applicant’s telephone number and email address;
- (e) the applicant’s website address, if any;
- (f) the name, mailing address, telephone number and email address of an individual who may be contacted for inquiries related to the application;
- (g) a description of the applicant’s organizational structure, including its governance structure;
- (h) the name of every regulatory or supervisory body that oversees any of the applicant’s activities in Canada;
- (i) an indication of whether the applicant has been registered or accredited — or has applied for registration or accreditation — under a consumer-driven banking framework in any other country and, if so, the name of the country and the date and current status of the registration, accreditation or application;
- (j) a declaration that the applicant is in compliance with the security safeguards referred to in section 37;
- (k) the name, date of birth, title, brief job description, telephone number and email address of the officer or employee whom the applicant intends to designate under section 80 of the Act if it becomes a participating entity;
- (l) the contact information that consumers will be able to use to make complaints to the applicant if it becomes a participating entity;
- (m) evidence of the applicant’s compliance with the technical standard referred to in subsection 125(1) of the Act; and
- (n) the information referred to in section 25.
System
(2) The application must be made using the electronic system provided by the Bank for that purpose.
Application — registered payment service provider
4 (1) An application referred to in subsection 17(1) of the Act must contain
- (a) if the applicant is an entity, its legal name, any trade name under which it intends to provide services in accordance with the Act, the date, country and jurisdiction of its incorporation or other formation and, in the case of a corporation, its incorporation number and the legislation under which it is incorporated;
- (b) if the applicant is an individual, their name and date of birth;
- (c) the applicant’s primary civic and mailing addresses;
- (d) the applicant’s telephone number and email address;
- (e) the applicant’s website address, if any;
- (f) if the applicant is an entity, the name, mailing address, telephone number and email address of an individual who may be contacted for inquiries related to the application;
- (g) a declaration that the applicant has a place of business in Canada and the civic address of that place of business;
- (h) a declaration as to whether the applicant operates or plans to operate out of a dwelling-house;
- (i) if the applicant is an entity, a description of its organizational structure, including its governance structure;
- (j) the name of every regulatory or supervisory body that oversees any of the applicant’s activities in Canada;
- (k) an indication of whether the applicant has been registered or accredited — or has applied for registration or accreditation — under a consumer-driven banking framework in any other country and, if so, the name of the country and the date and current status of the registration, accreditation or application;
- (l) evidence of the independent third party’s confirmation referred to in paragraph 5(1)(b);
- (m) the name, date of birth, title, brief job description, telephone number and email address of the officer or employee whom the applicant intends to designate under section 80 of the Act if it becomes a participating entity;
- (n) the contact information that consumers will be able to use to make complaints to the applicant if it becomes a participating entity;
- (o) evidence of the applicant’s compliance with the technical standard referred to in subsection 125(1) of the Act;
- (p) evidence of the insurance or guarantee referred to in paragraph 5(1)(d);
- (q) if the applicant is an entity, a description of the policy required under paragraph 5(1)(e), the name, title and brief job description of all individuals who will have significant responsibility for the applicant’s consumer-driven banking activities and an attestation that those individuals have been assessed in accordance with that policy;
- (r) if the applicant is an individual, an attestation that they are of good character and information in support of that attestation; and
- (s) the information referred to in section 25.
System
(2) The application must be made using the electronic system provided by the Bank for that purpose.
Requirements — registered payment service provider
5 (1) For the purpose of subsection 17(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:
- (a) it must have a place of business in Canada;
- (b) it must have obtained, from a sufficiently skilled independent third party, confirmation of its implementation of the security safeguards referred to in section 37;
- (c) it must be in compliance with the technical standard referred to in subsection 125(1) of the Act;
- (d) it must hold insurance or a guarantee sufficient to cover its risks in relation to its management of data under the consumer-driven banking framework; and
- (e) if the applicant is an entity, it must have implemented a policy under which all individuals who will have significant responsibility for its consumer-driven banking activities are regularly assessed to ensure their integrity and good character and are required to report to it any changes in circumstances that may affect that assessment or, if the applicant is an individual, they must be of good character.
Continuation of requirements
(2) A participating entity that is accredited under subsection 17(1) of the Act must continue to be a registered payment service provider and meet the requirements set out in paragraphs (1)(a), (d) and (e).
Application — other entity
6 (1) An application referred to in subsection 19(1) of the Act must contain
- (a) the applicant’s legal name and any trade name under which the applicant intends to provide services in accordance with the Act;
- (b) the date, country and jurisdiction of its incorporation or other formation and, in the case of a corporation, its incorporation number and the legislation under which it is incorporated;
- (c) the applicant’s primary civic and mailing addresses;
- (d) the applicant’s telephone number and email address;
- (e) the applicant’s website address, if any;
- (f) the name, mailing address, telephone number and email address of an individual who may be contacted for inquiries related to the application;
- (g) a declaration that the applicant has a place of business in Canada and the civic address of that place of business;
- (h) a declaration as to whether the applicant operates or plans to operate out of a dwelling-house;
- (i) a description of the applicant’s organizational structure, including its governance structure;
- (j) the name of every regulatory or supervisory body that oversees any of the applicant’s activities in Canada;
- (k) an indication of whether the applicant has been registered or accredited — or has applied for registration or accreditation — under a consumer-driven banking framework in any other country and, if so, the name of the country and the date and current status of the registration, accreditation or application;
- (l) evidence of the independent third party’s confirmation referred to in paragraph 7(1)(b);
- (m) the name, date of birth, title, brief job description, telephone number and email address of the officer or employee whom the applicant intends to designate under section 80 of the Act if it becomes a participating entity;
- (n) a description of the manner in which the applicant intends to fulfill the requirements of subsection 92(1) and section 95 of the Act if it becomes a participating entity;
- (o) a description of the procedures that the applicant intends to establish under paragraph 105(1)(a) of the Act, the titles and brief job descriptions of the officers or employees that the applicant intends to designate under paragraphs 105(1)(b) and (c) of the Act and the contact information that consumers will be able to use to make complaints to the applicant if it becomes a participating entity;
- (p) a declaration as to whether the applicant is or has applied to be a member of the external complaints body;
- (q) evidence of the applicant’s compliance with the technical standard referred to in subsection 125(1) of the Act;
- (r) the estimated number of consumers whose data the applicant expects to share in accordance with the Act if it becomes a participating entity;
- (s) evidence of the insurance or guarantee referred to in paragraph 7(1)(d);
- (t) a description of the policy required under paragraph 7(1)(e), the name, title and brief job description of all individuals who will have significant responsibility for the applicant’s consumer-driven banking activities and an attestation that those individuals have been assessed in accordance with that policy; and
- (u) the information referred to in section 25.
System
(2) The application must be made using the electronic system provided by the Bank for that purpose.
Requirements — other entity
7 (1) For the purpose of subsection 19(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:
- (a) it must have a place of business in Canada;
- (b) it must have obtained, from a sufficiently skilled independent third party, confirmation of its implementation of the security safeguards referred to in section 37;
- (c) it must be in compliance with the technical standard referred to in subsection 125(1) of the Act;
- (d) it must hold insurance or a guarantee sufficient to cover its risks in relation to its management of data under the consumer-driven banking framework; and
- (e) it must have implemented a policy under which all individuals who will have significant responsibility for its consumer-driven banking activities are regularly assessed to ensure their integrity and good character and are required to report to it any changes in circumstances that may affect that assessment.
Continuation of requirements
(2) A participating entity that is accredited under subsection 19(1) of the Act must continue to meet the requirements set out in paragraphs (1)(a), (d) and (e).
Accreditation fee
8 (1) For the purposes of subsections 15(2), 17(2) and 19(2) of the Act, the accreditation fee is to be determined by the following formula and rounded to the nearest multiple of $100 or, if the result obtained is equidistant from two multiples of $100, to the higher of them:
- $2,500 Ă— (A Ă· B)
- where
- A
- is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year immediately before the year in which the application is made; and
- B
- is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year in which this section comes into force.
Exception
(2) Despite subsection (1), the fee to be included with an application for accreditation that is made in the calendar year in which this section comes into force is $2,500.
No decrease
(3) Despite subsection (1), if a fee determined under that subsection is less than the fee that was required to be included with an application made in the previous calendar year, the fee is instead equal to the fee applicable in that previous year.
Review of refusal to accredit
9 (1) For the purpose of subsection 21(1) of the Act, the period within which an applicant may make a request to the Governor for a review of the decision to refuse its application for accreditation is 30 days beginning on the day after the day on which the applicant is notified of that decision.
Decision of Governor
(2) For the purpose of subsection 21(2) of the Act, the period within which the Governor must accredit the applicant or confirm the refusal to accredit is 120 days beginning on the day after the day on which the Governor gives the applicant an opportunity to make representations.
Request for revocation
10 The other information that a participating entity must provide to consumers under paragraph 22(1)(b) of the Act is the following:
- (a) its name and the name, telephone number and email address of a representative of the participating entity who may be contacted regarding the revocation of its accreditation;
- (b) the day on which it plans to make the request for revocation;
- (c) its assessment of the impact that the revocation will have on the consumers, including an indication of any products or services that will no longer be available to them and when;
- (d) an indication that consumers whose data it has received must request the data’s deletion if they do not want the participating entity to retain it; and
- (e) information about the process for resolving outstanding complaints.
Notice of intent to revoke accreditation
11 (1) For the purpose of subsection 26(1) of the Act, the period within which a participating entity may make a request to the Governor for a review of a notice of intent to revoke its accreditation is 30 days beginning on the day after the day on which it is given the notice of intent.
Decision of Governor
(2) For the purpose of subsection 26(2) of the Act, the period within which the Governor must revoke the participating entity’s accreditation or withdraw the notice of intent is 60 days beginning on the day after the day on which the Governor gives the participating entity an opportunity to make representations.
Former participating entity
12 The other information that a former participating entity must provide to consumers under section 29 of the Act is the following:
- (a) its name and the name, telephone number and email address of a representative of the former participating entity who may be contacted regarding the revocation of its accreditation;
- (b) the day on which its accreditation was revoked;
- (c) the reasons for the revocation;
- (d) its assessment of the impact that the revocation will have on the consumers, including an indication of any products or services that will no longer be available to them and when;
- (e) an indication that consumers whose data it has received must request the data’s deletion if they do not want the former participating entity to retain it; and
- (f) information about the process for resolving outstanding complaints.
Accreditation as a Third-Party Service Provider
Application
13 (1) An application referred to in subsection 32(1) of the Act must contain
- (a) if the applicant is an entity, its legal name, any trade name under which it intends to perform any of the activities referred to in paragraphs 31(a) to (c) of the Act, the date, country and jurisdiction of its incorporation or other formation and, in the case of a corporation, its incorporation number and the legislation under which it is incorporated;
- (b) if the applicant is an individual, their name and date of birth;
- (c) the applicant’s primary civic and mailing addresses;
- (d) the applicant’s telephone number and email address;
- (e) the applicant’s website address, if any;
- (f) if the applicant is an entity, the name, mailing address, telephone number and email address of an individual who may be contacted for inquiries related to the application;
- (g) a declaration that the applicant has a place of business in Canada and the civic address of that place of business;
- (h) a declaration as to whether the applicant operates or plans to operate out of a dwelling-house;
- (i) if the applicant is an entity, a description of its organizational structure, including its governance structure;
- (j) the name of every regulatory or supervisory body that oversees any of the applicant’s activities in Canada;
- (k) an indication of whether the applicant has been registered or accredited — or has applied for registration or accreditation — under a consumer-driven banking framework in any other country and, if so, the name of the country and the date and current status of the registration, accreditation or application;
- (l) if the applicant is an entity, a description of the policy required under paragraph 14(1)(b), the name, title and brief job description of all individuals who will have significant responsibility for the applicant’s performance of the activities referred to in paragraphs 31(a) to (c) of the Act and an attestation that those individuals have been assessed in accordance with that policy;
- (m) if the applicant is an individual, an attestation that they are of good character and information in support of that attestation;
- (n) an indication of the activities referred to in paragraphs 31(a) to (c) of the Act that the applicant intends to perform on behalf of a participating entity;
- (o) the names of the participating entities for which the applicant intends to perform activities referred to in paragraphs 31(a) to (c) of the Act, if known;
- (p) the names of any entities for which the applicant
- (i) performed, in another country in the previous two years, activities similar to those referred to in paragraphs 31(a) to (c) of the Act
- (ii) intends to perform, in another country in the next two years, activities similar to those referred to in paragraphs 31(a) to (c) of the Act; and
- (q) the information referred to in section 25.
System
(2) The application must be made using the electronic system provided by the Bank for that purpose.
Requirements
14 (1) For the purpose of subsection 32(1) of the Act, the requirements that the Bank must be satisfied that an applicant meets are the following:
- (a) it must have a place of business in Canada; and
- (b) if the applicant is an entity, it must have implemented a policy under which all individuals who will have significant responsibility for its performance of the activities referred to in paragraphs 31(a) to (c) of the Act are regularly assessed to ensure their integrity and good character and are required to report to it any changes in circumstances that may affect that assessment or, if the applicant is an individual, they must be of good character.
Continuation of requirements
(2) An accredited third-party service provider must continue to meet the requirements referred to in subsection (1).
Accreditation fee
15 (1) For the purpose of subsection 32(2) of the Act, the accreditation fee is to be determined by the following formula and rounded to the nearest multiple of $100 or, if the result obtained is equidistant from two multiples of $100, to the higher of them:
- $2,500 Ă— (A Ă· B)
- where
- A
- is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year immediately before the year in which the application is made; and
- B
- is the September all-items Consumer Price Index for Canada, as published by Statistics Canada under the Statistics Act, for the calendar year in which this section comes into force.
Exception
(2) Despite subsection (1), the fee to be included with an application for accreditation that is made in the calendar year in which this section comes into force is $2,500.
No decrease
(3) Despite subsection (1), if a fee determined under that subsection is less than the fee that was required to be included with an application made in the previous calendar year, the fee is instead equal to the fee applicable in that previous year.
Review of refusal to accredit
16 (1) For the purpose of subsections 34(1) of the Act, the period within which an applicant may make a request to the Governor for a review of the decision to refuse its application for accreditation is 30 days beginning on the day after the day on which the applicant is notified of that decision.
Decision of Governor
(2) For the purpose of subsection 34(2) of the Act, the period within which the Governor must accredit the applicant or confirm the refusal to accredit is 120 days beginning on the day after the day on which the Governor gives the applicant an opportunity to make representations.
Notice of intent to revoke accreditation
17 (1) For the purpose of subsection 39(1) of the Act, the period within which an accredited third-party service provider may make a request to the Governor for a review of a notice of intent to revoke its accreditation is 30 days beginning on the day after the day on which it is given the notice of intent.
Decision of Governor
(2) For the purpose of subsection 39(2) of the Act, the period within which the Governor must revoke the third-party service provider’s accreditation or withdraw the notice of intent is 60 days beginning on the day after the day on which the Governor gives the third-party service provider an opportunity to make representations.
Former accredited third-party service provider
18 The other information that a former accredited third-party service provider must provide to participating entities under section 42 of the Act is the following:
- (a) its name and the name, telephone number and email address of a representative of the former accredited third-party service provider who may be contacted regarding the revocation of its accreditation;
- (b) the day on which its accreditation was revoked; and
- (c) a description of the impact that the revocation will have on the participating entities.
Appeal to Federal Court
Period
19 For the purpose of subsection 43(1) of the Act, the period within which an applicant may appeal to the Federal Court a decision referred to in subsection 21(3) of the Act, a participating entity may appeal to the Federal Court a decision referred to in subsection 26(3) of the Act or an accredited third-party service provider may appeal to the Federal Court a decision referred to in subsection 34(3) or 39(3) of the Act is 30 days beginning on the day after the day on which the applicant, the participating entity or the accredited third-party service provider, as the case may be, is notified of the decision.
Registry
Name and address
20 For the purposes of paragraphs 44(a) and (f) of the Act, the names and addresses that must be included in the registry are the legal and any trade names of each participating entity and accredited third-party service provider and their primary civic and mailing addresses.
Other information
21 For the purposes of paragraphs 44(e) and (h) of the Act, the other information that must be included in the registry is the following:
- (a) the telephone number, email address and, if any, website address of each participating entity and accredited third-party service provider;
- (b) any conditions that the Bank has imposed under subsection 23(3) or 36(3) of the Act on each participating entity or accredited third-party service provider whose accreditation has been suspended;
- (c) the contact information that consumers may use to make complaints to each participating entity; and
- (d) the list of activities referred to in paragraphs 31(a) to (c) of the Act that each accredited third-party service provider performs and the names of all of the participating entities on whose behalf that accredited third-party service provider performs those activities.
Updating
22 The registry must be updated immediately after any of the information referred to in section 44 of the Act changes or, in the case of information of which the Bank must be notified, immediately after the Bank is notified of the change or the change takes effect, whichever is later.
National Security
Interpretation
Affiliation, subsidiaries and control
23 For the purposes of this section and section 25,
- (a) an entity is affiliated with another entity if one of them is the subsidiary of the other or if both are subsidiaries of the same entity or are controlled by the same individual;
- (b) two entities are affiliated with each other if they are affiliated with the same entity at the same time;
- (c) an individual and an entity are affiliated with each other if the individual controls the entity;
- (d) an entity is a subsidiary of another entity if it is controlled by that other entity;
- (e) a corporation is controlled by an individual or entity if
- (i) securities to which are attached more than 50% of the votes that may be cast to elect the corporation’s directors are held, directly or indirectly, whether through one or more subsidiaries or otherwise, other than by way of security only, by or for the benefit of that individual or entity, and
- (ii) the votes attached to those securities are sufficient, if exercised, to elect a majority of the corporation’s directors;
- (f) a limited partnership is controlled by its general partner;
- (g) an entity other than a corporation or a limited partnership is controlled by an individual or other entity if that individual or other entity holds, directly or indirectly, whether through one or more subsidiaries or otherwise, an ownership interest in the entity that entitles the individual or other entity to receive more than 50% of the profits of that entity or more than 50% of its assets on dissolution; and
- (h) an entity is controlled by an individual or other entity if that individual or other entity has any direct or indirect influence that, if exercised, would result in control in fact of the entity.
Definition of senior officer
24 In paragraph 25(g), senior officer means
- (a) a member of the applicant’s board of directors who is also one of its full-time employees;
- (b) the applicant’s chief executive officer, chief operating officer, president, chief risk officer, secretary, treasurer, controller, chief financial officer, chief accountant, chief auditor or chief actuary, or any person who performs functions similar to those normally performed by someone occupying one of those positions; or
- (c) any other officer who reports directly to the its board of directors, chief executive officer or chief operating officer.
Application for Accreditation
Information to be provided in application
25 The following information is to be provided for the purposes of paragraphs 3(1)(n), 4(1)(s), 6(1)(u) and 13(1)(q):
- (a) an indication of whether the applicant is publicly traded and, if so, the name of the exchanges on which it is traded;
- (b) if the applicant is an individual, their countries of citizenship;
- (c) if the applicant is an entity, an organization chart that
- (i) identifies each individual or entity that is affiliated with the applicant and the nature of the affiliation,
- (ii) identifies each individual or entity that holds — or for whose benefit is held — directly or indirectly,
- (A) in the case of an applicant that is a corporation, securities to which are attached 10% or more of the votes that may be cast to elect the applicant’s directors, unless they are held by way of security only, or
- (B) in the case of an applicant that is an entity other than a corporation or limited partnership, an ownership interest in the applicant that entitles the individual or entity to receive 10% or more of the applicant’s profits or 10% or more of its assets on dissolution,
- (iii) identifies each individual or entity, other than one referred to in subparagraph (ii), that controls the applicant,
- (iv) for each individual or entity referred to in subparagraph (ii) or (iii), indicates the percentage of votes that they hold in the applicant or their interest in the applicant,
- (v) for each individual referred to in subparagraph (ii) or (iii), indicates their countries of residence and citizenship, and
- (vi) for each entity referred to in subparagraph (ii) or (iii), indicates its country and jurisdiction of incorporation or other formation;
- (d) in respect of each of the following entities, its legal name and any trade names, its mailing address, the civic address of its head office, its telephone number, its email address, its website address, if any, and the date, country and jurisdiction of its incorporation or other formation:
- (i) an entity that is affiliated with the applicant,
- (ii) an entity referred to in subparagraph (c)(ii) or (iii),
- (iii) an entity that holds — or for whose benefit is held — directly or indirectly,
- (A) securities to which are attached 10% or more of the votes that may be cast to elect the directors of a corporation that controls the applicant, unless they are held by way of security only, or
- (B) an ownership interest in another entity that is not a corporation and that controls the applicant that entitles the entity to receive 10% or more of the other entity’s profits or 10% or more of its assets on dissolution;
- (e) in respect of each of the following individuals, their name, date of birth and countries of citizenship, the civic address of their primary place of residence and their mailing address, telephone number and email address:
- (i) an individual who is affiliated with the applicant,
- (ii) an individual who is referred to in subparagraph (c)(ii) or (iii),
- (iii) an individual who holds — or for whose benefit is held — directly or indirectly,
- (A) securities to which are attached 10% or more of the votes that may be cast to elect the directors of a corporation that controls the applicant, unless they are held by way of security only, or
- (B) an ownership interest in an entity that is not a corporation and that controls the applicant that entitles the individual to receive 10% or more of the entity’s profits or 10% or more of its assets on dissolution;
- (f) in respect of each member of the applicant’s board of directors, if any, their name, date of birth and countries of citizenship, the civic address of their primary place of residence and their mailing address, telephone number and email address, as well as an indication of whether they are a member of the board of directors of any other entities and, if so, the names of those entities;
- (g) in respect of each of the applicant’s five senior officers, if any, who were, for the last calendar year, the most highly compensated, having regard to all forms of compensation, including stock options, performance-based incentives and other benefits, their name, date of birth and countries of citizenship, the civic address of their primary place of residence, their mailing address, telephone number, email address and position title and a description of their main responsibilities;
- (h) in respect of each of the five creditors to which the applicant owed the greatest amount at any time during the last calendar year,
- (i) the creditor’s telephone number and email address,
- (ii) if the creditor is an individual, their name, date of birth and countries of citizenship, the civic address of their primary place of residence and their mailing address,
- (iii) if the creditor is an entity, its legal name, the country and jurisdiction of its incorporation or other formation, the civic address of its head office and its mailing address, telephone number and email address, and
- (iv) a description of the terms of the credit agreement;
- (i) an indication of whether a state-owned enterprise, as defined in section 3 of the Investment Canada Act, holds — or has held for its benefit — directly or indirectly, an ownership interest or voting interest in the applicant and, if so, the name of the state-owned enterprise and of the applicable foreign state and a description of the interest, including, in the case of a voting interest, an indication of whether it has a special veto or other decision-making right attached to it;
- (j) an indication of whether a state-owned enterprise, as defined in section 3 of the Investment Canada Act, has the power to appoint the chief executive officer or other senior management officers of the applicant, or members of its board of directors or a similar body, and, if so, the name of the state-owned enterprise and the applicable foreign state and a description of that power;
- (k) a list of all categories of personal or financial information, including the following categories, that the applicant gathers or plans to gather in respect of its consumers, employees or business partners and the purposes for which the information is gathered:
- (i) personal identifying information,
- (ii) financial data, including confidential account information,
- (iii) private communications, and
- (iv) geolocation data;
- (l) all countries in which the applicant or its third-party service providers store or process, or plan to store or process, any information referred to in paragraph (k); and
- (m) in respect of every individual or entity, other than an employee or agent or mandatary of the applicant, that may be given access to any information referred to in paragraph (k),
- (i) their telephone number and email address,
- (ii) in the case of an individual, their name, date of birth and countries of citizenship, the civic address of their primary place of residence and their mailing address, and
- (iii) in the case of an entity, its legal name, the country and jurisdiction of its incorporation or other formation, the civic address of its head office and its mailing address.
Decision to review
26 (1) For the purpose of subsection 47(1) of the Act, the period within which the Minister may decide to review an application for accreditation is 60 days beginning on the day after the day on which the Minister is provided with a copy of the application.
Extension of period
(2) For the purpose of subsection 47(2) of the Act, each period for which the period referred to in subsection (1) may be extended is 60 days.
Review
27 (1) For the purpose of subsection 48(1) of the Act, the period within which the Minister must conduct a review of an application for accreditation is 180 days beginning on the day after the day on which Minister decides to review the application.
Extension of period
(2) For the purpose of subsection 48(2) of the Act, each period for which the period referred to in subsection (1) may be extended is 180 days.
Review of directive
28 For the purpose of subsection 53(1) of the Act, the period within which an applicant may request a review by the Minister of a directive to the Bank to refuse accreditation is 30 days beginning on the day after the day on which the Bank notifies the applicant that their application for accreditation has been refused.
Additional information
29 For the purpose of subsection 54(2) of the Act, the period within which an applicant must provide the requested information to the Bank is 30 days beginning on the day after the day on which the applicant receives the request.
Suspension and Revocation
Review of notice of intent
30 For the purpose of subsection 67(1) of the Act, the period within which a participating entity or accredited third-party service provider may request a review by the Minister of a notice of the Minister’s intent to issue a directive to the Bank to revoke the participating entity’s or accredited third-party service provider’s accreditation is 30 days beginning on the day after the day on which the Bank notifies the participating entity or accredited third-party service provider of the notice of intent.
Former participating entity
31 The other information that a former participating entity must provide to consumers under subsection 69(4) of the Act is the following:
- (a) its name and the name, telephone number and email address of a representative of the former participating entity who may be contacted regarding the revocation of its accreditation;
- (b) the day on which its accreditation was revoked;
- (c) its assessment of the impact that the revocation will have on the consumers, including an indication of any products or services that will no longer be available to them and when;
- (d) an indication that consumers whose data it has received must request the data’s deletion if they do not want the former participating entity to retain it; and
- (e) information about the process for resolving outstanding complaints.
Former accredited third-party service provider
32 The other information that a third-party service provider whose accreditation has been revoked must provide to participating entities under subsection 69(5) of the Act is the following:
- (a) its name and the name, telephone number and email address of a representative of the former accredited third-party service provider who may be contacted regarding the revocation of its accreditation;
- (b) the day on which its accreditation was revoked; and
- (c) a description of the impact that the revocation will have on the participating entities.
Additional information
33 For the purpose of subsection 71(2) of the Act, the period within which a participating entity or accredited third-party service provider must provide the requested information to the Bank is 15 days beginning on the day after the day on which the participating entity or accredited third-party service provider receives the request.
Duties of Participating Entities
Data Sharing
Verification
34 A participating entity must not share a consumer’s data under subsection 76(1) of the Act unless
- (a) in the case of a participating entity that has been requested to provide a consumer’s data, it verifies the identity of the requesting entity and confirms, with reference to the registry, that that entity is a participating entity and that its accreditation has not been suspended or, if it has been suspended, that the Bank has not imposed, under subsection 23(3) of the Act, any conditions on that entity that would preclude it from receiving the requested data; and
- (b) in the case of a participating entity that is requesting to receive a consumer’s data, it verifies the identity of the entity to which the request is made and confirms, with reference to the registry, that that entity is a participating entity and that its accreditation has not been suspended or, if it has been suspended, that the Bank has not imposed, under subsection 23(3) of the Act, any conditions on that entity that would preclude it from providing the requested data.
Exceptions to duty to share
35 (1) A participating entity is not required under subsection 76(1) of the Act to share a consumer’s data with another participating entity if
- (a) it has reasonable grounds to believe that doing so would cause physical, psychological or financial harm to the consumer;
- (b) it has reasonable grounds to believe that doing so would adversely impact the security, integrity or stability of the consumer-driven banking framework or of a participating entity’s information and communication technology systems; or
- (c) the account to which the data relates has been blocked or suspended.
Data older than 24 months
(2) Subsection 76(1) of the Act does not apply in relation to
- (a) data referred to in paragraph 2(d) with respect to balances or amounts that were owing more than 24 months prior;
- (b) data referred to in paragraph 2(e) that pertains to a transaction that was completed more than 24 months prior; or
- (c) data referred to in paragraph 2(f) that pertains to products or services that were available or offered to the consumer more than 24 months prior.
Notice to Bank
(3) For greater certainty, a participating entity’s obligation under subsection 76(4) of the Act to notify the Bank that it is not sharing a consumer’s data as required by subsection 76(1) of the Act applies to situations where the reason for not sharing is that one of the circumstances referred to in subsection (1) of this section exists or the consumer’s consent has not yet been renewed following a circumstance referred to in subsection 44(1) or section 46.
Notice to other participating entity
(4) A participating entity that does not share a consumer’s data because of one of the circumstances referred to in subsection (1) or because the consumer’s consent has not yet been renewed following a circumstance referred to in subsection 44(1) must notify the other participating entity of the reason for not sharing the data.
Requirements
36 (1) A participating entity that shares a consumer’s data under subsection 76(1) of the Act must
- (a) ensure that its response times are consistent with generally accepted international standards;
- (b) ensure that any electronic system that it uses to share the data is operational at least 99.5% of the time in a calendar month, apart from any planned outages; and
- (c) use traffic management measures, including rate-limiting, throttling and preferencing, only as necessary for ensuring the technical stability or security of that system and only in a manner that is proportionate and non-discriminatory, does not degrade outcomes for consumers and does not prevent other participating entities or accredited third-party service providers from effectively performing activities in accordance with the Act.
Planned outages
(2) For the purpose of paragraph (1)(b), planned outages are outages of which the Bank is notified at least one week in advance — or, if they are necessary to resolve a critical service or security issue, as soon as feasible — and whose duration and frequency are commensurate to outages of the participating entity’s consumer-facing electronic systems.
Security
Security safeguards
37 (1) For the purpose of section 79 of the Act, the security safeguards are the following:
- (a) the development and application of procedures for identifying and remedying vulnerabilities in the participating entity’s systems, software and processes in relation to the integrity and security of data in respect of which the Act applies, including procedures for ensuring that the participating entity’s systems and software are regularly updated to minimize those vulnerabilities;
- (b) the use of a secure configuration as the default setting on all devices used for accessing systems that are used for sharing and storing data in respect of the which the Act applies;
- (c) the use of security software on all systems used for sharing and storing data in respect of which the Act applies and on all devices used for accessing those systems;
- (d) the use of robust authentication methods on all systems used for sharing and storing data in respect of which the Act applies and on all devices used for accessing those systems;
- (e) the development and application of policies on access management, including policies to restrict access to data in respect of which the Act applies and to systems and facilities through which that data can be accessed based on user roles and responsibilities;
- (f) the provision of unique accounts to all users of — and to all software or systems that interact with — systems that are used for sharing and storing data in respect of which the Act applies and the application of policies to minimize the use of shared accounts;
- (g) the encryption and regular backing up of stored data in respect of which the Act applies;
- (h) the use of robust network security controls to help protect data in respect of which the Act applies while it is in transit;
- (i) the development and application of a policy on the use of external storage to prevent the unauthorized transfer of data in respect of which the Act applies;
- (j) a prohibition against the connection of unauthorized devices to systems used for sharing and storing data in respect of which the Act applies;
- (k) a prohibition against the installation of unauthorized applications on systems used for sharing and storing data in respect of which the Act applies and on devices used for accessing those systems;
- (l) the use of security software that monitors and controls network traffic on systems through which data in respect of which the Act applies can be accessed;
- (m) the application of measures to identify and quarantine or block suspicious content that is received by the participating entity;
- (n) the keeping of an up-to-date inventory of all systems and devices that are used in relation to the sharing and storing of data in respect of which the Act applies, including a brief description of how each of those systems and devices is used;
- (o) the inclusion of terms, in any contract with a third-party service provider, to ensure the third-party service provider’s protection of data obtained or used for the purpose of performing activities for the participating entity;
- (p) the development of and provision to employees of a training program on recognizing and preventing cyber threats and the application of procedures for keeping the program up to date; and
- (q) the development and execution of an incident response plan that
- (i) sets out procedures for promptly detecting and for responding to and recovering from incidents in which the security or integrity of data in respect of which the Act applies is or could be compromised, including procedures for the auditing of system logs to make incidents more traceable, and
- (ii) requires the periodic performance of exercises based on extreme but plausible scenarios to test the procedures referred to in subparagraph (i) and identify and remedy gaps in incident response actions and capabilities.
Proportionality
(2) The implementation of the security safeguards must be proportionate to the sensitivity of the data and the participating entity may segment its network into various security zones to ensure an adequate level of protection for all data.
Federal or provincial financial institution
(3) A federal financial institution or a provincial financial institution is presumed to have implemented the security safeguards unless the Superintendent of Financial Institutions or the appropriate provincial authority that regulates or supervises the provincial financial institution has identified deficiencies in that entity’s ability to protect itself against threats to the integrity and security of its data and has directed it to take remedial measures.
Designation of responsible officer or employee
38 A participating entity must, without delay after designating an officer or employee under section 80 of the Act, provide the Bank with that individual’s name, title, brief job description, telephone number and email address.
Report of breach to Bank
39 A report under subsection 82(1) of the Act must contain
- (a) a description of the circumstances of the breach and, if known, its cause;
- (b) the day on which, or period during which, the breach occurred or, if that information is unknown, the approximate day or period;
- (c) a description of the consumer data that is the subject of the breach, if known;
- (d) the number of consumers whose data is the subject of the breach — or, if that number is unknown, the approximate number — and the potential impact of the breach on those consumers;
- (e) the potential impacts of the breach on the participating entity’s consumer-driven banking activities and on other participating entities or accredited third-party service providers;
- (f) a description of the steps that the participating entity has taken to reduce or mitigate any harm to affected consumers that could result from the breach;
- (g) a description of the steps that the participating entity has taken or intends to take to notify affected consumers of the breach under subsection 82(3) of the Act, if applicable; and
- (h) the name, telephone number and email address of a person who can answer, on behalf of the participating entity, the Bank’s questions about the breach.
Notice to consumer of breach
40 (1) A notice given under subsection 82(3) of the Act must contain
- (a) the information referred to in paragraphs 39(a) to (c) and (f);
- (b) a description of the steps that affected consumers could take to reduce or mitigate the risk of harm that is created by the breach; and
- (c) the contact information that affected consumers may use to obtain further information about the breach.
Manner
(2) For the purpose of subsection 82(5) of the Act and subject to subsection (3), the notice must be given directly to the consumer in person, by telephone, by mail, by email or using any other form of communication that a reasonable person would consider appropriate in the circumstances.
Exception — indirect notice
(3) If the participating entity does not have any contact information for the affected consumer that would allow them to give notice in accordance with subsection (2), or if giving notice in that manner would be likely to cause further harm to the affected consumer or undue hardship for the participating entity, the participating entity must give the notice by public communication or similar means that could reasonably be expected to reach the affected consumer.
Investigation of breach
41 The conclusions that are reported to the Bank under section 83 of the Act must address the following subjects and must be reported as soon as feasible using the electronic system provided by the Bank for that purpose:
- (a) the root causes of the breach;
- (b) the breach’s impact on the participating entity’s consumer-driven banking activities;
- (c) the breach’s impact on other participating entities and on accredited third-party service providers;
- (d) the breach’s impact on consumers; and
- (e) actions taken or to be taken by the participating entity to prevent a similar breach from occurring.
Consent
Use of data
42 Despite subsection 85(6) of the Act, a participating entity may use a consumer’s data that it receives from another participating entity for a use other than those described in the information provided to the consumer under paragraph 85(4)(b) of the Act if
- (a) the participating entity has reasonable grounds to believe the data could be useful in the investigation of a contravention of the laws of Canada, a province or a foreign jurisdiction that has been, is being or is about to be committed, and the data is used for the purpose of investigating that contravention;
- (b) the data is used for the purpose of acting in respect of an emergency that threatens the life, health or security of an individual; or
- (c) the data is publicly available.
Record of consent
43 (1) Each record of express consent that is kept by a participating entity under subsection 85(8) of the Act must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept in a format that is — or can readily be made — intelligible to the Bank until the day that is five years after the day on which the consent ceases to be valid.
Protective measures
(2) The participating entity must take reasonable measures with respect to the record to
- (a) prevent its loss or destruction;
- (b) prevent its falsification;
- (c) detect and correct any inaccuracies contained in it; and
- (d) prevent unauthorized persons from accessing or using the information contained in it.
Renewal of consent
44 (1) For the purpose of subsection 87(1) of the Act, the circumstances in which a participating entity must renew a consumer’s express consent are the following:
- (a) the consumer’s authentication information has been stolen or otherwise exposed to imminent risk;
- (b) there has been a significant change to the consumer’s circumstances that would reasonably call into question whether the consumer would provide consent in those circumstances;
- (c) there has been a significant change to the participating entity that would reasonably call into question whether the consumer would provide consent for their data to be provided to that participating entity; and
- (d) another participating entity has requested, under section 93 of the Act, that the participating entity renew the express consent.
Initiation
(2) The participating entity must initiate the renewal process as soon as feasible after it becomes aware of a circumstance referred to in subsection (1).
Deletion of data
45 (1) For greater certainty, a participating entity is not required, under subsections 87(5) and 90(4) of the Act, to delete data that has been irreversibly and permanently modified to ensure that there is no reasonably foreseeable risk in the circumstances that the consumer can be identified from it, whether directly or indirectly, by any means.
Notice to consumer
(2) A participating entity that does not delete certain data whose deletion is requested by a consumer because the deletion is prohibited by law or is not required under subsection (1) must notify the consumer as soon as feasible, in writing, of the reasons for not deleting the data. If the deletion is prohibited by law but that situation is expected to be temporary, the notice must also indicate when the participating entity will be able to delete the data and must confirm that the deletion will be completed without further action by the consumer.
Request for renewal
46 For the purpose of section 93 of the Act, a request by a participating entity to another participating entity that the latter renew a consumer’s express consent must be made as soon as feasible after
- (a) the participating entity that provides the consumer’s data becomes aware that the consumer’s authentication information has been stolen or otherwise exposed to imminent risk;
- (b) the participating entity that provides the consumer’s data becomes aware that there has been a significant change to the consumer’s circumstances that would reasonably call into question whether the consumer would provide consent in those circumstances; or
- (c) there has been a significant change to the participating entity that provides the consumer’s data that would reasonably call into question whether the consumer would provide consent for their data to be provided by that participating entity.
Consumer Authentication
Requirements
47 (1) To enable a participating entity that provides a consumer’s data to comply with its duties under subsection 92(1) of the Act, a participating entity that requests a consumer’s data for the first time during any period for which the consumer’s consent has been obtained or renewed must, with the knowledge of the consumer, redirect the consumer to the participating entity from which the data is requested for confirmation of the consumer’s authentication information and must advise the participating entity from which the data is requested of the duration and scope of the consumer’s consent.
Participating entity that provides data
(2) A participating entity that receives a request to provide a consumer’s data must, if and only if it is the first such request received by the participating entity during a period for which the consumer’s consent has been obtained or renewed and regardless of the manner in which the consumer accesses the participating entity’s products or services,
- (a) confirm the consumer’s authentication information using multi-factor authentication;
- (b) obtain the consumer’s acknowledgement of the name of the participating entity that has requested the data, the nature of the request and the accounts from which the requested data will be provided; and
- (c) once the requirements set out in paragraphs (a) and (b) have been met, share the consumer’s data with the participating entity that requested the data and redirect the consumer to that participating entity.
Consumer Measures
Display of sign
48 (1) The sign that is displayed by a participating entity for the purpose of paragraph 94(a) of the Act must be clearly visible during business hours from the main customer area of the location in question.
False impression
(2) The location and manner in which a sign is displayed under section 94 of the Act must not give the impression that an individual or entity is a participating entity, or that data relating to a particular product or service is subject to the consumer-driven banking framework, if that is not the case.
Provision of Information
Notice of change
49 (1) For the purpose of subsection 98(1) of the Act, the changes of which the participating entity must notify the Bank are changes to
- (a) any of its names or contact information;
- (b) its organizational structure;
- (c) in the case of a participating entity that is accredited under subsection 17(1) of the Act, its registration under the Retail Payment Activities Act;
- (d) the oversight of any of its activities in Canada by a regulatory or supervisory body;
- (e) its registration or accreditation under a consumer-driven banking framework in any other country or its application for such registration or accreditation;
- (f) the contact information for the officer or employee designated under section 80 of the Act;
- (g) the telephone number or email address that consumers may use to make complaints;
- (h) its membership in the external complaints body;
- (i) in the case of a participating entity that is accredited under section 17 or 19 of the Act, the individuals with significant responsibility for its consumer-driven banking activities or the integrity and good character of those individuals;
- (j) in the case of a participating entity that is accredited under section 17 or 19 of the Act, its insurance or guarantee, to the extent that the insurance or guarantee is no longer sufficient to cover the participating entity’s risks in relation to its management of data under the consumer-driven banking framework;
- (k) its compliance with the technical standard referred to in subsection 125(1) of the Act; and
- (l) any of the information referred to in section 25.
Timing
(2) For the purpose of subsection 98(2) of the Act, the period within which the notice must be given is
- (a) in respect of a change referred to in any of paragraphs (1)(a) to (g), 30 days beginning on the day after the day on which the change occurs;
- (b) in respect of a change referred to in any of paragraphs (1)(h) to (k), as soon as feasible after the participating entity becomes aware of the change, even if it has already taken effect; and
- (c) in respect of a change referred to in paragraph (1)(l),
- (i) as soon as feasible after the participating entity becomes aware of a change to any of the following information, even if the change has already taken effect:
- (A) the information referred to in any of paragraphs 25(a) to (j), or
- (B) a telephone number, email address or mailing address referred to in paragraph 25(m),
- (ii) at least 30 days before the day on which a change to any of the following information takes effect:
- (A) the information referred to in paragraph 25(k), or
- (B) the information referred to in paragraph 25(m), other than the information referred to in clause (i)(B) of this paragraph, and
- (iii) at least 60 days before the day on which a change to the information referred to in paragraph 25(l) takes effect.
- (i) as soon as feasible after the participating entity becomes aware of a change to any of the following information, even if the change has already taken effect:
Annual report
50 (1) The information that must be included in the report that a participating entity submits to the Bank under section 100 of the Act is the following:
- (a) for each month in the reporting year,
- (i) the number of times that the participating entity did not share a consumer’s data as required by subsection 76(1) of the Act — including because of each of the circumstances referred to in subsection 35(1), subsection 44(1) and section 46 — and the reasons for not sharing the data,
- (ii) the number of consumers from which it obtained express consent, the number of express consents and renewals of express consent obtained and the number of withdrawals of consent of which it was notified,
- (iii) the number of requests that it received under subsection 87(5) of the Act to delete a consumer’s data,
- (iv) the percentage of time that any electronic system that it uses to share consumer data in accordance with the Act was operational, apart from any planned outages,
- (v) the number of other participating entities with which it shared consumer data,
- (vi) the number of times it provided a consumer’s data to another participating entity and, of those, the number of times the other participating entity received the data, and
- (vii) the average response time for providing a consumer’s data to another participating entity and that data being received;
- (b) a summary of all of the changes referred to in subsection 79(2) of the Act or section 49 of these Regulations that occurred during the reporting year;
- (c) a description of any changes made during the reporting year to the policies and procedures that the participating entity established under section 81, subsection 96(3) or section 101 of the Act or to the procedures that it established under subsection 105(1) of the Act;
- (d) a summary of any breaches referred to in subsection 82(1) of the Act that occurred during the reporting year;
- (e) a description of any planned or unplanned outages of any electronic system used by the participating entity for sharing data in accordance with the Act that occurred during the reporting year;
- (f) a declaration that, as of the end of the reporting year, the participating entity was in compliance with the technical standard referred to in subsection 125(1) of the Act;
- (g) a description of the participating entity’s financial metrics, including its revenues, gross profits or losses, operating profits or losses, assets, liabilities and equity as of the end of the reporting year;
- (h) if the participating entity is a federal financial institution or a provincial financial institution, a declaration that the Superintendent of Financial Institutions or the appropriate provincial authority that regulates or supervises the provincial financial institution has not, during the reporting year, identified deficiencies in the entity’s ability to protect itself against threats to the integrity and security of its data or, if deficiencies have been identified, that the entity has taken all remedial measures that it has been directed to take; and
- (i) if the participating entity is accredited under section 17 or 19 of the Act, a description of the manner in which it has implemented the security safeguards referred to in section 37.
Definition of reporting year
(2) In this section, reporting year means the participating entity’s financial year in respect of which the report is submitted to the Bank.
Record Keeping
Duty to keep records
51 (1) The records that a participating entity must keep under section 102 of the Act are those sufficient to demonstrate its compliance with the Act and these Regulations.
Period of retention
(2) The records must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept until the day that is five years after the day on which the records cease to demonstrate the participating entity’s current compliance with the Act and these Regulations.
Form
(3) The records must be kept, in electronic form, in a format that is — or can readily be made — intelligible to the Bank.
Protective measures
(4) The participating entity must take reasonable measures with respect to the records to
- (a) prevent their loss or destruction;
- (b) prevent their falsification;
- (c) detect and correct any inaccuracies contained in them; and
- (d) prevent unauthorized persons from accessing or using the information contained in them.
Liability
Safeguarding of authentication information
52 Every participating entity
- (a) must inform its consumers of the consequences, under subsection 103(1) of the Act, of demonstrating gross negligence — or, in Quebec, gross fault — in safeguarding their authentication information;
- (b) must advise its consumers of reasonable measures they can take to safeguard their authentication information; and
- (c) must not intentionally mislead its consumers about the extent of their liability or adopt policies under which consumers are presumed to be liable contrary to subsections 103(1) and (3) of the Act.
Liability of participating entities
53 For greater certainty, if, under subsection 103(1) of the Act, a consumer is not liable for a financial loss arising from the loss of, unauthorized access to or unauthorized use of their data that occurs in relation to the sharing of data in accordance with the Act, liability as between the participating entities involved in the sharing of that data is, for the purpose of section 104 of the Act, to be determined as follows:
- (a) the participating entity that requests the data is liable to the extent that the data loss, access or use from which the financial loss arises occurs in relation to that participating entity’s seeking of the consumer’s consent to request their data, its making of that request or its receipt of the requested data; and
- (b) the participating entity that provides the data is liable to the extent that the data loss, access or use from which the financial loss arises occurs in relation to that participating entity’s receipt of the request to provide the consumer’s data, its confirmation of information under subsection 92(1) of the Act or its preparation and provision of the requested data.
Duties of Accredited Third-Party Service Providers
Provision of Information
Notice of change
54 (1) For the purpose of subsection 120(1) of the Act, the changes of which the accredited third-party service provider must notify the Bank are changes to
- (a) any of its names or contact information,
- (b) its organizational structure;
- (c) its registration or accreditation under a consumer-driven banking framework in any other country or its application for such registration or accreditation;
- (d) the activities referred to in paragraphs 31(a) to (c) of the Act that it performs for participating entities or the participating entities for which it performs those activities;
- (e) the entities for which it intends to perform, in another country in the next two years, activities similar to those referred to in paragraphs 31(a) to (c) of the Act;
- (f) the individuals with significant responsibility for its performance of the activities referred to in paragraphs 31(a) to (c) of the Act or the integrity and good character of those individuals; and
- (g) any of the information referred to in section 25.
Timing
(2) For the purpose of subsection 120(2) of the Act, the period within which the notice must be given is
- (a) in respect of a change referred to in any of paragraphs (1)(a) to (c), 30 days beginning on the day after the day on which the change occurs;
- (b) in respect of a change referred to in any of paragraphs (1)(d) to (f), as soon as feasible after the accredited third-party service provider becomes aware of the change, even if it has already taken effect; and
- (c) in respect of a change referred to in paragraph (1)(g),
- (i) as soon as feasible after the accredited third-party service provider becomes aware of a change to any of the following information, even if the change has already taken effect:
- (A) the information referred to in any of paragraphs 25(a) to (j), or
- (B) a telephone number, email address or mailing address referred to in paragraph 25(m),
- (ii) at least 30 days before the day on which a change to any of the following information takes effect:
- (A) the information referred to in paragraph 25(k), or
- (B) the information referred to in paragraph 25(m), other than the information referred to in clause (i)(B) of this paragraph, and
- (iii) at least 60 days before the day on which a change to the information referred to in paragraph 25(l) takes effect.
- (i) as soon as feasible after the accredited third-party service provider becomes aware of a change to any of the following information, even if the change has already taken effect:
Record Keeping
Duty to keep records
55 (1) The records that an accredited third-party service provider must keep under section 122 of the Act are the following:
- (a) those sufficient to demonstrate its compliance with the Act and these Regulations;
- (b) a copy of each of its contracts with a participating entity under which it performs any of the activities referred to in paragraphs 31(a) to (c) of the Act, including any revisions to those contracts; and
- (c) a copy of its policies and procedures, if any, relating to its performance, on behalf of a participating entity, of the activities referred to in paragraphs 31(a) to (c) of the Act, including any revisions to those policies and procedures.
Period of retention
(2) The records must, subject to any undertaking provided for the purpose of section 55 of the Act or any term or condition imposed under section 56 of the Act, be kept until the day that is five years after the day on which
- (a) in the case of a record referred to in paragraph (1)(a), it ceases to demonstrate the accredited third-party service provider’s current compliance with the Act and these Regulations; or
- (b) in the case of a record referred to in paragraph (1)(b) or (c), the contract, policy or procedure ceases to be valid.
Form
(3) The records must be kept, in electronic form, in a format that is — or can readily be made — intelligible to the Bank.
Protective measures
(4) The accredited third-party service provider must take reasonable measures with respect to the records to
- (a) prevent their loss or destruction;
- (b) prevent their falsification;
- (c) detect and correct any inaccuracies contained in them; and
- (d) prevent unauthorized persons from accessing or using the information contained in them.
Technical Standards Body
Annual report
56 (1) For the purpose of section 128 of the Act, the annual report that must be submitted to the Bank by the technical standards body must include the following information in relation to the year in respect of which the report is submitted:
- (a) a description of any vulnerability in the technical standard referred to in subsection 125(1) of the Act or in the technical standards body that, during that year, had or could have had an impact on the security of data being shared by participating entities, including the circumstances in which the vulnerability was discovered, the cause of the vulnerability, if known, the actual or potential impacts of the vulnerability, the measures taken by the technical standards body to mitigate the vulnerability and the name, telephone number and email address of a person who can answer the Bank’s questions about the vulnerability on behalf of the technical standards body;
- (b) a non-technical description of any changes or updates that were made during the year to the data fields that are required by the technical standard, to the features or functionality of the technical standard or to any other aspect of the technical standard that affects the security of data sharing, as well as the rationale for those changes or updates and a description of the technical standard body’s decision-making process that led to them being made; and
- (c) a description of any changes that were made during the year that could be relevant to the technical standards body’s designation, taking into account the factors referred to in subsection 125(2) of the Act.
Time and manner
(2) The report must be submitted using the electronic system provided by the Bank for that purpose within seven days following each anniversary of the day on which the Minister’s order designating the body as the technical standards body comes into force.
Evidentiary Privilege
Supervisory information
57 For the purpose of subsection 133(1) of the Act, the information that must not be used as evidence in any civil proceedings and that is privileged for that purpose is the following:
- (a) any direction, notice, letter, plan, report or recommendation that is issued or prepared by the Bank in connection with its supervision of a participating entity or an accredited third-party service provider under the Act;
- (b) any compliance agreement referred to in section 147 of the Act; and
- (c) any correspondence between the Bank and an applicant for accreditation, a participating entity, an accredited third-party service provider, the external complaint body or the technical standards body — or between the external complaints body or technical standards body and an applicant for accreditation, a participating entity or an accredited third-party service provider — that relates to the Bank’s supervision of participating entities or accredited third-party service providers under the Act.
Use of information
58 (1) For the purpose of subsection 133(3) of the Act, the Minister, the Governor, the Bank and the Attorney General of Canada may use the information referred to in section 57 of these Regulations as evidence in any proceeding.
Certain Acts
(2) For the purpose of subsection 133(4) of the Act, a participating entity or accredited third-party service provider may use the information referred to in section 57 of these Regulations as evidence in any proceeding referred to in that subsection.
Assessment of Fees
Participating entities
59 (1) For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed, in respect of a calendar year, against an individual or entity that was a participating entity at any time during that calendar year is to be determined by the formula
- A + B − C
- where
- A
- is the base assessment amount determined under subsection (2) for the participating entity in respect of the calendar year;
- B
- is the variable assessment amount determined under subsection (3) for the participating entity in respect of the calendar year; and
- C
- is the amount of any interim assessment made against the participating entity under subsection 140(4) of the Act during the calendar year.
Base assessment amount
(2) The base assessment amount for a participating entity in respect of a calendar year is
- (a) in the case of a participating entity whose total assets on December 31 of the calendar year have a value greater than or equal to $1 trillion dollars, $150,000;
- (b) in the case of a participating entity whose total assets on December 31 of the calendar year have a value greater than or equal to $100 billion but less than $1 trillion, $100,000;
- (c) in the case of a participating entity whose total assets on December 31 of the calendar year have a value greater than or equal to $10 billion but less than $100 billion, $50,000;
- (d) in the case of a participating entity whose total assets on December 31 of the calendar year have a value greater than or equal to $1 billion but less than $10 billion, $20,000; and
- (e) in the case of a participating entity whose total assets on December 31 of the calendar year have a value less than $1 billion, $10,000.
Variable assessment amount
(3) The variable assessment amount for a participating entity in respect of a calendar year is
- (a) in the case of a participating entity referred to in paragraph (2)(a), the amount determined by the formula
- 0.4 Ă— (D − E − F − G) Ă· H
- where
- D
- is the amount ascertained for the calendar year under subsection 140(1) of the Act, following the deduction of the accreditation fees,
- E
- is the total of all base assessment amounts determined under subsection (2) in respect of the calendar year,
- F
- is the total of all assessments under section 60 and any interim assessments made against accredited third-party service providers in respect of the calendar year,
- G
- is the total of all assessments under section 61 and any interim assessments made against the external complaints body in respect of the calendar year, and
- H
- is the number of participating entities referred to in paragraph (2)(a);
- (b) in the case of a participating entity referred to in paragraph (2)(b), the amount determined by the formula
- 0.3 Ă— (D − E − F − G) Ă· J
- where
- D
- is the amount ascertained for the calendar year under subsection 140(1) of the Act, following the deduction of the accreditation fees,
- E
- is the total of all base assessment amounts determined under subsection (2) in respect of the calendar year,
- F
- is the total of all assessments under section 60 and any interim assessments made against accredited third-party service providers in respect of the calendar year,
- G
- is the total of all assessments under section 61 and any interim assessments made against the external complaints body in respect of the calendar year, and
- J
- is the number of participating entities referred to in paragraph (2)(b);
- (c) in the case of a participating entity referred to in paragraph (2)(c), the amount determined by the formula
- 0.2 Ă— (D − E − F − G) Ă· K
- where
- D
- is the amount ascertained for the calendar year under subsection 140(1) of the Act, following the deduction of the accreditation fees,
- E
- is the total of all base assessment amounts determined under subsection (2) in respect of the calendar year,
- F
- is the total of all assessments under section 60 and any interim assessments made against accredited third-party service providers in respect of the calendar year,
- G
- is the total of all assessments under section 61 and any interim assessments made against the external complaints body in respect of the calendar year, and
- K
- is the number of participating entities referred to in paragraph (2)(c);
- (d) in the case of a participating entity referred to in paragraph (2)(d), the amount determined by the formula
- 0.1 Ă— (D − E − F − G) Ă· L
- where
- D
- is the amount ascertained for the calendar year under subsection 140(1) of the Act, following the deduction of the accreditation fees,
- E
- is the total of all base assessment amounts determined under subsection (2) in respect of the calendar year,
- F
- is the total of all assessments under section 60 and any interim assessments made against accredited third-party service providers in respect of the calendar year,
- G
- is the total of all assessments under section 61 and any interim assessments made against the external complaints body in respect of the calendar year, and
- L
- is the number of participating entities referred to in paragraph (2)(d); and
- (e) in the case of a participating entity referred to in paragraph (2)(e), nil.
Assets of subsidiaries
(4) For the purpose of this section, the value of a participating entity’s total assets excludes the value of the assets of any subsidiary of the entity that is itself a participating entity.
Accredited third-party service providers
60 For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed, in respect of a calendar year, against an individual or entity that was an accredited third-party service provider at any time during that calendar year is $10,000, less the amount of any interim assessment that was made against the accredited third-party service provider under subsection 140(4) of the Act during the calendar year.
External complaints body
61 (1) For the purpose of subsection 140(3) of the Act, the portion of the amount ascertained by the Bank under subsection 140(1) of the Act that is to be assessed in respect of a calendar year against the external complaints body is, subject to subsection (2), $50,000, less the amount of any interim assessment that was made against the external complaints body under subsection 140(4) of the Act during the calendar year.
Partial calendar year
(2) The amount that is to be assessed in respect of a calendar year against a corporation that was designated as the external complaints body for only a portion of that year is to be reduced proportionally.
Request for information
62 (1) For the purpose of subsection 141(1) of the Act, the period within which the requested information must be provided to the Bank is
- (a) in the case of a request for information relating to a participating entity’s total assets on December 31 of a calendar year that is made on or before that day, the period beginning on January 1 and ending on March 31 of the following calendar year; and
- (b) in any other case, 15 days beginning on the day after the day on which the request is made.
Value of assets
(2) Despite subsections 59(2) and (3), if a participating entity fails to provide requested information about the value of its assets within the period referred to in paragraph (1)(a), the base assessment amount and variable assessment amount for that participating entity are to be determined as if the participating entity were a participating entity referred to in paragraph 59(2)(a).
Administrative Monetary Penalties
Designation of violations
63 The following are designated as violations under paragraph 155(1)(a) of the Act:
- (a) the contravention of any of the following provisions of the Act:
- (i) section 11,
- (ii) subsection 23(5),
- (iii) section 29,
- (iv) section 31,
- (v) subsection 36(5),
- (vi) section 42,
- (vii) subsection 69(4) or (5),
- (viii) subsection 76(1), (2), (3) or (4),
- (ix) section 77,
- (x) section 78(1),
- (xi) subsection 79(1) or (2),
- (xii) section 80,
- (xiii) section 81,
- (xiv) subsection 82(1), (2), (3), (4), (5) or (6),
- (xv) section 83,
- (xvi) section 84,
- (xvii) subsection 85(1), (3), (4), (5), (6), (7) or (8),
- (xviii) subsection 87(3), (4) or (5),
- (xix) section 88,
- (xx) section 89,
- (xxi) subsection 90(2), (3) or (4),
- (xxii) subsection 91(2),
- (xxiii) subsection 92(1) or (2),
- (xxiv) section 93,
- (xxv) paragraph 94(a) or (b),
- (xxvi) section 95,
- (xxvii) subsection 96(1), (2) or (3),
- (xxviii) section 97,
- (xxix) subsection 98(1) or (2),
- (xxx) section 99,
- (xxxi) section 100,
- (xxxii) section 101,
- (xxxiii) section 102,
- (xxxiv) paragraph 105(1)(a), (b) or (c) or subsection 105(2), (3) or (4),
- (xxxv) section 106,
- (xxxvi) section 107,
- (xxxvii) section 108,
- (xxxviii) section 109,
- (xxxix) section 110,
- (xl) section 111,
- (xli) section 112,
- (xlii) subsection 114(3)
- (xliii) any of paragraphs 115(b) to (t),
- (xliv) section 116,
- (xlv) section 117,
- (xlvi) section 118,
- (xlvii) subsection 120(1) or (2),
- (xlviii) section 121,
- (xlix) section 122,
- (l) section 128,
- (li) section 129,
- (lii) section 130,
- (liii) subsection 141(2),
- (liv) subsection 142(2),
- (lv) subsection 143(4) or (5),
- (lvi) subsection 145(2),
- (lvii) section 173;
- (b) the contravention of any of the following provisions of these Regulations:
- (i) subsection 35(4),
- (ii) section 36,
- (iii) section 38,
- (iv) subsection 43(1) or (2),
- (v) subsection 44(2),
- (vi) subsection 45(2),
- (vii) subsection 47(1) or (2),
- (viii) subsection 48(1) or (2),
- (ix) subsection 51(2), (3) or (4),
- (x) section 52,
- (xi) subsection 55(2), (3) or (4); and
- (c) non-compliance with
- (i) a compliance agreement entered into under section 147 of the Act, or
- (ii) a direction made under subsection 148(1), (2), (3), (4), (5) or (7) of the Act.
Coming into Force
S.C. 2026, c. 3, s. 224
64 (1) Subject to subsections (2) and (3), these Regulations come into force on the day on which section 44 of the Consumer-Driven Banking Act comes into force, but if they are registered after that day, they come into force on the day on which they are registered.
S.C. 2026, c. 3, s. 224
(2) Sections 34 to 36, 38 to 55 and 63, other than subparagraph 63(a)(liii), come into force on the day on which section 76 of the Consumer-Driven Banking Act comes into force, but if these Regulations are registered after that day, those provisions come into force on the day on which these Regulations are registered.
S.C. 2026, c. 3, s. 224
(3) Sections 59 to 62 and subparagraph 63(a)(liii) come into force on the day on which section 140 of the Consumer-Driven Banking Act comes into force, but if these Regulations are registered after that day, those provisions come into force on the day on which these Regulations are registered.
Terms of use and Privacy notice
Terms of use
It is your responsibility to ensure that the comments you provide do not:
- contain personal information
- contain protected or classified information of the Government of Canada
- express or incite discrimination on the basis of race, sex, religion, sexual orientation or against any other group protected under the Canadian Human Rights Act or the Canadian Charter of Rights and Freedoms
- contain hateful, defamatory, or obscene language
- contain threatening, violent, intimidating or harassing language
- contain language contrary to any federal, provincial or territorial laws of Canada
- constitute impersonation, advertising or spam
- encourage or incite any criminal activity
- contain external links
- contain a language other than English or French
- otherwise violate this notice
The federal institution managing the proposed regulatory change retains the right to review and remove personal information, hate speech, or other information deemed inappropriate for public posting as listed above.
Confidential Business Information should only be posted in the specific Confidential Business Information text box. In general, Confidential Business Information includes information that (i) is not publicly available, (ii) is treated in a confidential manner by the person to whose business the information relates, and (iii) has actual or potential economic value to the person or their competitors because it is not publicly available and whose disclosure would result in financial loss to the person or a material gain to their competitors. Comments that you provide in the Confidential Business Information section that satisfy this description will not be made publicly available. The federal institution managing the proposed regulatory change retains the right to post the comment publicly if it is not deemed to be Confidential Business Information.
Your comments will be posted on the Canada Gazette website for public review. However, you have the right to submit your comments anonymously. If you choose to remain anonymous, your comments will be made public and attributed to an anonymous individual. No other information about you will be made publicly available.
Comments will remain posted on the Canada Gazette website for at least 10 years.
Please note that communication by email is not secure, if the attachment you wish to send contains sensitive information, please contact the departmental email to discuss ways in which you can transmit sensitive information.
Privacy notice
The information you provide is collected under the authority of the Financial Administration Act, the Department of Public Works and Government Services Act, the Canada–United States–Mexico Agreement Implementation Act,and applicable regulators’ enabling statutes for the purpose of collecting comments related to the proposed regulatory changes. Your comments and documents are collected for the purpose of increasing transparency in the regulatory process and making Government more accessible to Canadians.
Personal information submitted is collected, used, disclosed, retained, and protected from unauthorized persons and/or agencies pursuant to the provisions of the Privacy Act and the Privacy Regulations. Individual names that are submitted will not be posted online but will be kept for contact if needed. The names of organizations that submit comments will be posted online.
Submitted information, including personal information, will be accessible to Public Services and Procurement Canada, who is responsible for the Canada Gazette webpage, and the federal institution managing the proposed regulatory change.
You have the right of access to and correction of your personal information. To seek access or correction of your personal information, contact the Access to Information and Privacy (ATIP) Office of the federal institution managing the proposed regulatory change.
You have the right to file a complaint to the Privacy Commission of Canada regarding any federal institution’s handling of your personal information.
The personal information provided is included in Personal Information Bank PSU 938 Outreach Activities. Individuals requesting access to their personal information under the Privacy Act should submit their request to the appropriate regulator with sufficient information for that federal institution to retrieve their personal information. For individuals who choose to submit comments anonymously, requests for their information may not be reasonably retrievable by the government institution.