Submission of the Office of the Privacy Commissioner of Canada on Consumer-Driven Banking Regulations
August 26, 2026
Kïrsten Fraser
Director, Financial Services Innovation
Financial Services Division
Financial Sector Policy Branch
Department of Finance Canada
90 Elgin Street
Ottawa, Ontario
K1A 0G5
Email: obbo@fin.gc.ca
Subject: OPC Submission on Consumer-Driven Banking Regulations
Dear Kïrsten Fraser,
The Office of the Privacy Commissioner of Canada (OPC) would like to thank Finance Canada for the opportunity to provide comments on the proposed Consumer-Driven Banking Regulations, as published in the Canada Gazette, Part I, Volume 160, Number 26, on June 27, 2026 (Regulations).Footnote 1
The OPC oversees compliance with both the Privacy Act,Footnote 2 which covers the personal information handling practices of federal government institutions, and the Personal Information Protection and Electronic Documents Act (PIPEDA),Footnote 3 which is Canada’s federal private-sector privacy law.
During his appearance before the House of Commons Standing Committee on Industry and Technology on January 26, 2026, Commissioner Philippe Dufresne expressed support for consumer-driven banking as a data mobility framework that would give Canadians greater control of their personal information by allowing them to make decisions about who they want their information shared with.Footnote 4
The OPC supports the aims of the consumer-driven banking regime, which would allow consumers to direct where their data is going in a safe and secure way, and to prohibit the privacy-invasive practice of screen scraping.
Several elements of the proposed Regulations would help to ensure that consumers’ privacy is protected, including: (1) the requirements related to participating entities’ reporting of breaches of security safeguards to the Bank of Canada, (2) the requirement for participating entities receiving a request to share data to use multi-factor authentication, and (3) the requirement for participating entities to inform consumers of the consequences of demonstrating gross negligence — or, in Quebec, gross fault — in safeguarding their authentication information, and to advise consumers of reasonable measures that they can take to safeguard their authentication information. These measures will help to ensure that Canadians can benefit from innovative financial services while retaining control over their highly sensitive financial data and having assurance that it will be handled safely.
The OPC would also like to highlight some areas where privacy-protective measures could be enhanced, including with regards to the scope of data to which the framework applies, the accreditation criteria, the exception to consent for publicly available data, the security safeguards, and the shared oversight between the Bank of Canada and the OPC in terms of privacy.
Data Elements
Section 2 of the proposed Regulations lists the data elements that would be subject to the Consumer-Driven Banking Act (CDBA). These include: (a) data pertaining to the identity of consumers of the products or services; (b) account numbers, branch numbers and other identifiers pertaining to the products or services; (c) the terms under which the products or services are provided, including in relation to fees, interest rates and authorizations; (d) current or past balances owing; (e) data pertaining to completed, pending or pre-authorized transactions; and (f) data respecting the products or services that are available or offered to a consumer.Footnote 5
These data elements do not include sufficient detail to allow a consumer to know the exact information that would be captured. For example, “data pertaining to the identity of consumers of the products or services”Footnote 6 does not specify what data would be included. This can be contrasted with Australia’s Competition and Consumer (Consumer Data Right) Rules 2020, which govern Australia’s open-banking system and detail various elements that make up the broad data categories. For example, Australia’s rules state that “customer data” about an individual means “information that identifies or is about the person” and includes: (i) the person’s name; (ii) the person’s contact details, including their telephone number, email address and physical address; and (iii) any information that the person provided at the time of acquiring the product, and relates to their eligibility to acquire the product”.Footnote 7
Delineating the specific data elements would ensure that consumers are fully aware of the information that is subject to the framework. Accordingly, the OPC recommends that section 2 of the proposed Regulations be amended to include the specific data elements to which the CDBA applies.
Accreditation Criteria
The CDBA mandates participation of certain banks listed in Schedule 1 of the Bank ActFootnote 8 and allows other entities to opt-in through an accreditation process. The proposed Regulations set out criteria for four pathways of accreditation overseen by the Bank of Canada: (1) non-streamlined accreditation, (2) streamlined accreditation for entities registered under the Retail Payments Activities Act (RPAA), (3) accredited third-party service providers (ATPSPs) and (4) federal and provincial financial institutions. The proposed Regulations outline the minimum requirements that applicants must meet and the information that must be submitted to be accredited.
To ensure the effectiveness of the accreditation process, the OPC recommends that the accreditation criteria be amended to: (A) require the Bank to be satisfied that ATPSP applicants have implemented security safeguards appropriate to the sensitivity of data under subsection 14(1) of the Regulations and require ATPSP applicants to provide evidence of their implementation of the security safeguards, such as confirmation obtained from a sufficiently skilled independent third-party, under subsection 13(1) of the Regulations, (B) require streamlined and federal and provincial financial institution applicants to provide the Bank with information about the complaint procedures required by section 105 of the CDBA, (C) require ATPSP applicants that provide or receive data on behalf of a participating entity to submit evidence of compliance with the technical standard, (D) require federal and provincial financial institution applicants to demonstrate that persons with significant responsibility for consumer-driven banking have been assessed for good character and integrity and to demonstrate that they have insurance or other guarantees to manage risks with data management under the consumer-driven banking framework, and (E) require streamlined and federal and provincial financial institution applicants and ATPSPs who manage authentication on behalf of participating entities to provide information regarding consumer authentication and require streamlined and federal and provincial financial institution applicants to provide consumer dashboard information as required for non-streamlined applicants under paragraph 6(1)(n) of the proposed Regulations.
Exception to Consent for Publicly Available Data
Under paragraph 42(c) of the proposed Regulations, participating entities would be permitted to use data without consent for purposes other than those provided to the consumer if the data is publicly available.Footnote 9
The breadth of this exception may leave Canadians’ personal information vulnerable to improper use. In contrast, paragraph 7(2)(c.1) of PIPEDAFootnote 10 allows organizations to use personal information without the knowledge or consent of the individual if the information is publicly available and specified by the Regulations Specifying Publicly Available Information.Footnote 11 The Regulations under PIPEDA outline specific types of personal information that would be considered publicly available for the purpose of the consent exception. These are generally circumstances where individuals do not retain a reasonable expectation of privacy. To ensure that the consent exception under the proposed Regulations is sufficiently narrow, the OPC recommends that section 42 be amended to clarify that publicly available data does not include data in which a consumer has a reasonable expectation of privacy.
Security Safeguards
Section 37 of the proposed Regulations outlines security safeguards that entities would be required to implement, including: identifying and addressing system vulnerabilities; securing systems and devices through measures like authentication, encryption, network security, and providing employee training; and establishing and regularly testing incident-response plans to detect, respond to, and recover from security incidents.Footnote 12 The implementation of the prescribed safeguards must be proportionate to the sensitivity of the data.Footnote 13
Given the rapid pace of technological change, having a prescribed list of required safeguards may result in the prescribed safeguards being insufficient to address evolving security risks. As such, the OPC recommends that the Regulations be amended to include an overarching requirement for participating entities to protect data using security safeguards that are appropriate to the sensitivity of data. This could be added in addition to the specific safeguards currently prescribed by the Regulations, the implementation of which must be proportionate to the sensitivity of data.
The OPC’s Technology Analysis Division would be pleased to meet with Finance Canada to share further insights on security safeguards that could be required to ensure the secure transfer of data for consumer-driven banking.
Regulatory Cooperation
Considering the shared oversight role for the handling of personal information, including with respect to breaches of security safeguards, provisions that expressly provide for coordination and information sharing between the Bank of Canada and the OPC would help to ensure the efficient and effective oversight of the consumer-driven banking framework. Such provisions could be similar to subsections 37(5) and 64(3) of the Privacy ActFootnote 14 and section 15.1 of the National Security and Intelligence Review Agency Act,Footnote 15 which expressly authorize the OPC and the National Security and Intelligence Review Agency to coordinate the activities of their respective offices to avoid any unnecessary duplication of work, and to share information for that purpose.
The OPC recommends that the proposed Regulations be amended to add a provision clarifying that the agreements and arrangements that the Bank may enter into under section 5 of the Consumer-Driven Banking Act may provide for coordination of the respective activities of the Bank and of other government authorities and regulatory bodies, and for the sharing of information necessary for the purpose of such coordination. In that regard, section 23 of PIPEDA may serve as a model.
Conclusion
We appreciate the opportunity to share our views and would be pleased to engage with your officials on any of the issues raised in the submission.
Sincerely,
(Original signed by)
Lara Ives
Acting Deputy Commissioner
Legal Services and Policy Sector
Office of the Privacy Commissioner of Canada
- Date modified: