Canada Open Banking and Consumer Driven Banking Rules

Proposed Consumer Driven Banking Regulations
Canada Open Banking and Consumer Driven Banking Rules
Canada’s proposed Consumer Driven Banking Regulations establish the operating framework for open banking. They address accreditation, consumer consent, data sharing, security, technical standards, liability, complaints, reporting, national security review and enforcement.
Use this guide to understand the proposed requirements, the implementation work they create and the consultation questions that may affect banks, credit unions, payment service providers, fintechs, consumers and small businesses.
Consultation is open for 60 days through the Canada Gazette online commenting feature and closes August 26, 2026 at 11:59 p.m. EDT. Responses may be submitted through the Canada Gazette online commenting feature or by email to obbo@fin.gc.ca, citing Canada Gazette, Part I, June 27, 2026.
Canada’s Open Banking and Consumer Driven Banking Journey
Canada has advanced from open banking policy development into proposed Consumer Driven Banking Regulations under Bank of Canada oversight. The current stage is consultation on the draft operating rules.Impact Analysis
Key figures from the Regulatory Impact Analysis Statement and proposed regulations.Regulatory Intelligence Explorer
Navigate the proposed regulations by topic. Each section separates requirements, implementation work, consultation considerations and NCFA’s strategic perspective.Overview
- Definition of Act and prescribed covered data
- Accreditation applications for federal or provincial financial institutions, RPAA registered payment service providers, other entities and accredited third party service providers
- Bank of Canada electronic application system, accreditation fee, refusal review and revocation processes
- National security information package, Ministerial decision period, review period, extensions and review rights
- Registry based verification before sharing data and exceptions where sharing can be withheld
- Service standards for response times, endpoint availability, planned outages and traffic management
- Security safeguards, breach reporting and responsible officer reporting
- Authentication, acknowledgement and consent connected to secure data sharing
- Notices, annual reporting, record keeping, liability, complaints, technical standards body reporting, assessments and violations
- Whether the framework gives enough implementation runway between final regulations, Bank of Canada guidance and coming into force
- Whether proportionality is strong enough for small firms and RPAA registered payment service providers without reducing consumer trust
- Whether guidance should clarify connections between fraud, consent, complaints, liability, security events and record keeping
- Whether the technical standards body, conformance testing and service performance rules should be clearer before launch
- Whether the cost and reporting model supports competition or favours organizations with existing compliance infrastructure
- Whether consumers and SMEs will be able to understand which entities are accredited, which data is covered and how complaints or deletion requests work
Application and Data
- Identity related data for consumers of covered products or services
- Account numbers, branch numbers, transit numbers and other product or service identifiers
- Product and service terms, including fees, interest rates and authorizations
- Current and past balances or amounts owing
- Completed, pending and pre authorized transaction data
- Information about products or services available or offered to consumers, including terms
- Historical limits apply in the data sharing rules for balances, transactions and available or offered products and services older than 24 months
- Covered data must be tied to a valid data sharing request, participant verification, consumer authentication and consent
- Whether the covered data categories are specific enough for consistent implementation across institutions
- Whether the treatment of derived, inferred or enriched data needs clearer boundaries
- Whether the 24 month historical limit is sufficient for SME finance, lending, accounting and cash flow use cases
- Whether business accounts, joint accounts, delegated authority and multi user permissions need more detailed guidance
- Whether future open finance expansion should be signalled earlier to reduce later redesign
- Whether data quality, correction and dispute processes need a clearer connection to complaints and liability
Accreditation
- Federal or provincial financial institution applications include security compliance declaration, designated officer details, complaint contact, technical standard evidence and national security information
- RPAA registered PSP applications include Canadian place of business, dwelling house declaration, independent security confirmation, technical standard evidence, insurance or guarantee and integrity policy or good character information
- Other entity applications include similar information plus descriptions of how they will meet specified duties, complaint procedures, external complaints body membership and estimated consumer numbers
- RPAA registered PSPs and other entities must maintain place of business, insurance or guarantee and integrity or good character requirements after accreditation
- The accreditation fee is $2,500 in the first year and then indexed to September CPI, rounded to the nearest $100, with no decrease from the previous year
- An applicant has 30 days to request Governor review of an accreditation refusal, and the Governor has 120 days after giving an opportunity to make representations to accredit or confirm refusal
- Participating entities requesting voluntary revocation must provide consumers with name and contact, planned request date, impact assessment, deletion notice and complaint resolution information
- A participating entity has 30 days to request Governor review of a notice of intent to revoke accreditation, and the Governor has 60 days after giving an opportunity to make representations to revoke or withdraw the notice
- Former participating entities must notify consumers of revocation date, reasons, impact, deletion request requirement and complaint process
- Accredited third party service provider applications include legal information, activity description, participating entity relationships, Canadian place of business, independent security confirmation, technical standard evidence, contract and policy information and national security information
- Whether application evidence is proportionate across banks, credit unions, RPAA registered PSPs, other entities and ATPSPs
- Whether the independent third party confirmation of security safeguards should have defined qualifications or assurance standards
- Whether insurance or guarantee sufficiency needs guidance so applicants can price participation
- Whether the dwelling house declaration could create unnecessary ambiguity for remote first firms
- Whether refusal, revocation and review timelines are workable for firms planning launch and funding milestones
- Whether ATPSP accreditation requirements are clear enough for infrastructure providers that will support multiple participating entities
Authentication and Consent
- Requester and provider verification against the registry before sharing
- Confirmation that accreditation has not been suspended or restricted by Bank conditions
- Multi factor authentication of the consumer’s authentication information
- Consumer acknowledgement of the requesting entity, nature of the request and relevant accounts
- Data sharing only after verification, authentication and acknowledgement requirements are met
- Renewal may be required after circumstances where data sharing was not required or consent has not yet been renewed
- Consent evidence must connect to records, deletion requests, liability, complaints and annual reporting
- Whether the registry verification workflow is operationally clear for real time data sharing
- Whether MFA requirements align with existing bank and fintech authentication journeys
- Whether consumer acknowledgement wording should be standardized enough to prevent confusing consent screens
- Whether consent renewal triggers and failed renewal situations need clearer examples
- Whether consumer dashboards, consent receipts and cross provider visibility should be addressed in guidance
- Whether consent evidence is sufficient to resolve liability, complaint and deletion disputes
Data Sharing Duties
- Provider verifies requester identity and registry status before sharing
- Requester verifies provider identity and registry status before requesting or receiving
- No duty to share where harm, security, integrity, stability or blocked account circumstances apply
- Balances or amounts owing more than 24 months old are outside the prescribed sharing duty
- Completed transactions more than 24 months old are outside the prescribed sharing duty
- Information about products or services available or offered more than 24 months earlier is outside the prescribed sharing duty
- Bank notice applies where data is not shared because of listed circumstances or non renewed consent
- The other participating entity must be notified of the reason for non sharing in specified circumstances
- Service responses must be consistent with generally accepted international standards
- Electronic systems used to share data must be operational at least 99.5 percent of each calendar month, excluding planned outages
- Traffic management such as rate limiting, throttling and preferencing may be used only for technical stability or security, must be proportionate and non discriminatory, must not degrade outcomes for consumers and must not prevent other participants or ATPSPs from effectively performing activities under the Act
- Planned outages require Bank notice at least one week in advance, or as soon as feasible for critical service or security issues, and duration and frequency must be commensurate with consumer facing system outages
- Whether the harm based exception is specific enough to apply consistently without becoming a broad refusal tool
- Whether 24 months is sufficient for lending, accounting, tax, underwriting and SME cash flow use cases
- Whether generally accepted international response time standards should be named or converted into measurable domestic standards
- Whether 99.5 percent uptime is high enough for financial infrastructure that may support operational workflows
- Whether traffic management restrictions need examples to prevent discriminatory API performance
- Whether planned outage notice and performance reporting should be visible to participants, consumers or the public
Security
- Vulnerability management and regular updates
- Secure configuration by default
- Security software on relevant systems and devices
- Robust authentication methods
- Role based access management policies
- Unique accounts and minimized shared accounts
- Encryption and regular backup of stored data
- Network security controls for data in transit
- External storage policy
- Prohibition on unauthorized devices and applications
- Monitoring and control of network traffic
- Suspicious content identification, quarantine or blocking
- Inventory of systems and devices used for sharing and storing covered data
- Contract terms requiring third party service provider protection of data
- Employee cyber threat training and ongoing updates
- Incident response plan with detection, response, recovery, log auditing and scenario exercises
- Responsible officer or employee details must be provided to the Bank without delay after designation
- Breach reports to the Bank must include circumstances, known cause, date or period, affected data, number of consumers, potential impacts, mitigation and contact information
- Whether the required safeguards are specific enough for consistent assurance while remaining technology neutral
- Whether independent third party confirmation should follow a defined assurance framework
- Whether breach reporting timing, consumer notification thresholds and report updates need more prescriptive examples
- Whether third party and cloud contract requirements should include subcontractor and data location obligations
- Whether small entrants can meet the same security evidence burden without shared infrastructure
- Whether fraud, identity, authentication and cyber controls should be addressed together in Bank guidance
Technical Standards
- Applicants must provide technical standard compliance evidence
- Participating entities must report annual technical standard compliance
- API or electronic system response times must align with generally accepted international standards
- Data sharing systems must meet 99.5 percent monthly availability, excluding planned outages
- Rate limiting, throttling and preferencing are restricted to stability and security purposes
- Traffic management must be proportionate, non discriminatory and must not degrade consumer outcomes
- Technical standards body annual report is due within seven days after each designation anniversary
- Technical standards body must report vulnerabilities, causes, impacts, mitigation and contact person
- Technical standards body must describe changes to data fields, features, functionality or security relevant aspects, plus rationale and decision process
- Technical standards body must describe changes relevant to its designation factors
- Whether the technical standards body should be identified or its governance clarified before final implementation planning
- Whether conformance testing should be mandatory before production access
- Whether response time expectations should be converted into measurable standards
- Whether 99.5 percent availability is sufficient for higher value financial workflows
- Whether public reporting of availability, outages and API performance would strengthen trust
- Whether technical standard changes should have notice periods, backwards compatibility expectations and migration timelines
Liability
- Consumers must be informed about gross negligence or gross fault consequences for authentication information
- Consumers must be advised of reasonable safeguarding measures
- Participants must not mislead consumers about liability
- Participants must not adopt policies presuming consumer liability contrary to the Act
- Requester liability follows failures connected to receiving or managing data
- Provider liability follows failures connected to authenticating the consumer or securely providing data
- Liability evidence depends on consent, authentication, registry checks, transmission logs, receipt records, complaint files and incident records
- Whether gross negligence or gross fault communications will be understandable for consumers
- Whether liability allocation is clear enough for multi party flows involving ATPSPs
- Whether examples should clarify direct financial loss, unauthorized access, data loss and failed revocation
- Whether consumer support and complaint processes need stronger alignment with liability rules
- Whether records required to prove liability should be specified more explicitly
- Whether fraud and scam scenarios are sufficiently covered by the liability architecture
Reporting Requirements
- Notice of change categories cover identity, structure, registration, oversight, foreign accreditation, officers, complaints, EBC membership, significant responsibility individuals, insurance or guarantee, technical standard compliance and national security information
- Notice timing includes 30 days after occurrence, as soon as feasible, at least 30 days before certain changes and at least 60 days before certain data storage or processing country changes
- Annual report metrics include monthly non sharing counts and reasons
- Annual report metrics include express consents, renewals, withdrawals and deletion requests
- Annual report metrics include uptime, data sharing counterparties, delivery counts and average response time
- Annual report must include changes, policy updates, breach summary, outages, technical compliance declaration and financial metrics
- Records must demonstrate compliance with the Act and regulations
- Records must be electronic and intelligible to the Bank
- Records must generally be kept for five years after they cease to demonstrate current compliance
- Records must be protected from loss, destruction, falsification, inaccuracies and unauthorized access or use
- ATPSPs must keep compliance records, contracts with participants and policies or procedures relating to services they perform for participants, with the same electronic form and protection rules
- Certain supervisory information, Bank directions, compliance agreements and supervisory correspondence are privileged for civil evidence purposes, with specified exceptions for use by the Minister, Governor, Bank, Attorney General of Canada, participants or ATPSPs in certain proceedings
- Whether the notice timing categories are clear enough for operational teams to apply consistently
- Whether annual reporting should align with RPAA and other Bank of Canada reporting regimes where possible
- Whether public transparency reporting on uptime, outages, complaints and non sharing events would strengthen trust
- Whether smaller firms need proportional reporting without weakening supervisory visibility
- Whether five year record retention is practical across all evidence categories
- Whether privileged supervisory information rules strike the right balance between supervision, litigation risk and transparency
Complaints
- Complaint contact information is required in accreditation applications
- Other entity applications must describe complaint procedures and designated complaint roles
- External complaints body membership status is required for certain applicants
- Revocation and former participant notices must include complaint resolution information
- Complaint processes connect to annual reporting and record keeping
- Complaint evidence should align with consent, authentication, data sharing, security, breach and liability records
- Whether complaint timelines and escalation expectations should be more explicit
- Whether consumers will know whether to contact the provider, requester, ATPSP, bank or external complaints body
- Whether SMEs need distinct complaint pathways for business account use cases
- Whether complaint data should feed into supervisory or public transparency reporting
- Whether complaints involving data quality, failed sharing, deletion or fraud require specific treatment
National Security Review
- Ownership, control, affiliates, significant influence and voting or ownership interest information
- Countries of residence, citizenship, incorporation or formation for relevant individuals and entities
- Board member and five most highly compensated senior officer information
- Five largest creditors and credit agreement terms
- State owned enterprise ownership, voting interest or appointment powers
- Categories of personal and financial information gathered or planned, including identifying information, financial data, private communications and geolocation data
- Countries where applicant or third party service providers store or process information
- Non employee or non agent individuals or entities that may access the information
- 60 day Ministerial decision window to review, extendable by 60 day periods
- 180 day national security review period, extendable by 180 day periods
- 30 day applicant review request period for refusal directive
- 30 day period to provide additional requested information under subsection 54(2)
- 30 day review request period for notice of intent to direct revocation
- 15 day period to provide additional information requested by the Bank under subsection 71(2)
- Whether the national security information package is proportionate for lower risk applicants
- Whether significant influence, creditor exposure and third party access require clearer guidance
- Whether data residency and cross border processing expectations should be clarified before applications begin
- Whether the 60 day and 180 day review timelines could materially affect investment, partnership and launch planning
- Whether applicants should have a pre filing process or informal guidance pathway for complex ownership structures
- Whether national security review should be harmonized with broader financial infrastructure, digital identity and cloud risk policy
Assessments and Fees
- $2,500 first year accreditation fee
- CPI indexed accreditation fee after first year, rounded to nearest $100 and not allowed to decrease
- Participating entity assessment equals base assessment plus variable assessment minus interim assessment
- Base assessment tiers of $150,000, $100,000, $50,000, $20,000 and $10,000 based on total assets
- Variable assessment shares of 0.4, 0.3, 0.2 and 0.1 for larger asset tiers
- No variable assessment for entities with less than $1 billion in assets
- ATPSP annual assessment of $10,000 less interim assessments
- External complaints body annual assessment of $50,000 less interim assessments, prorated for partial year designation
- Asset information deadline of March 31 in specified cases and 15 days in other cases
- Failure to provide asset information can result in assessment as if the entity were in the highest asset category
- Whether the base assessment tiers are proportionate for mid sized and smaller participants
- Whether the zero variable assessment for under $1 billion firms is enough to support competition
- Whether ATPSP fixed fees support shared infrastructure economics
- Whether asset based assessment is the right proxy for supervisory cost or market impact
- Whether fee predictability is sufficient for early entrants and investors
- Whether the highest tier default for missing asset information is too punitive or necessary for compliance discipline
Administrative Monetary Penalties
- Contraventions of numerous Act provisions are designated as violations
- Contraventions of selected regulation provisions are designated as violations
- Non compliance with compliance agreements is designated as a violation
- Non compliance with specified Bank directions is designated as a violation
- Regulation violations include non sharing notice failures, service standard failures, officer reporting failures, notice failures, annual reporting failures and record keeping failures
- Maximum penalty of $1 million for individuals
- Maximum penalty of $10 million for participating entities or ATPSPs
- Penalty exposure connects to accreditation, data sharing, registry use, privacy, security, breach reporting, authentication, consent, deletion, liability, complaints, technical standards, reporting, records and Bank information requests
- Coming into force is staged by Act sections, with most regulations coming into force when section 44 of the Act comes into force, data sharing and many operational obligations when section 76 comes into force, and assessment provisions when section 140 comes into force
- Whether violation categories are clear enough for participants to map controls before launch
- Whether penalty exposure is proportionate across firms of different size and role
- Whether remediation and self reporting should affect penalty treatment
- Whether public enforcement disclosure will be used to strengthen market discipline
- Whether staged coming into force gives firms enough time to build controls before penalties apply
- Whether individual exposure could affect senior officer recruitment and governance design
Related NCFA Intelligence
From Regulation to Opportunity
Canada’s proposed Consumer Driven Banking Regulations create readiness questions across accreditation, consent, data scope, APIs, cybersecurity, reporting, liability, supervision, national security review and enforcement. NCFA tracks commercial opportunities separately in the Open Banking in Canada Opportunity Brief, where regulatory evidence connects to product opportunities, investment themes, implementation gaps and emerging market signals.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |













Leave a Reply