The 60-second summary
On 26 August 2026, the Office of the Privacy Commissioner of Canada submitted recommendations on proposed Consumer-Driven Banking Regulations. The OPC supports secure consumer-directed data sharing, breach reporting to the Bank of Canada and multi-factor authentication. It recommends more specific data definitions, stronger accreditation evidence, complaint and dashboard requirements, a narrower consent exception for publicly available data, an overarching requirement for safeguards appropriate to data sensitivity, and express coordination between regulators. The regulations remain proposed. The 60-day consultation period closed on 26 August 2026, no final publication date has been announced, and commencement is intended to be staggered.
Timeline that matters
March 2026
Consumer-Driven Banking Act received royal assent
The Act established the legislative foundation for the supervised data-sharing framework.
27 June 2026
Proposed regulations published
Finance Canada opened a 60-day consultation on accreditation, consent, security, authentication, reporting, records and other operational requirements.
26 August 2026
OPC submission and consultation close
The privacy regulator published detailed recommendations on data scope, exceptions, safeguards, accreditation and regulatory cooperation.
Date not announced
Final publication expected
Final regulations would be published in the Canada Gazette, Part II after review of consultation input.
Staggered after final publication
Proposed commencement approach
Accreditation, common rules, fees and data categories would phase in; the full suite is intended within one year of final publication.
What changed
The legal proposal itself has not yet changed. The new development is the OPC’s formal privacy position as final drafting begins. The regulator supports the framework’s direction but recommends that broad data categories be replaced or supplemented with specific fields so consumers understand what is shared. It seeks stronger accreditation evidence, including security assurance, technical-standard compliance, complaint processes and dashboard information across more applicant pathways. It also recommends narrowing the proposed publicly available-data consent exception where a consumer retains a reasonable expectation of privacy, adding an overarching sensitivity-based safeguards duty and expressly enabling cooperation and information sharing between supervisors.
Who should pay attention?
Banks and participating financial institutions
The proposal would govern consent, authentication, data sharing, security, records, complaints and breach handling.
Fintechs and payment-service providers
Accreditation, technical standards, consent dashboards, security evidence and ongoing reporting may shape entry and operations.
Accredited third-party service providers
Providers performing consent, authentication or data-movement functions would face distinct accreditation and record-keeping expectations.
Privacy, security and product teams
The regulator is asking for clearer data scope, narrower reuse exceptions and safeguards tied to the sensitivity of financial information.
Procurement, assurance and incident teams
Independent evidence, complaint processes, vendor accountability and coordinated breach response are central implementation themes.
What the guidance clarifies
- The regulations remain proposed
- The OPC submission is a regulator recommendation to government; it does not itself amend the proposal or create a binding duty.
- The consultation period has closed
- The proposal was published on 27 June 2026 with a 60-day representation period, ending on 26 August 2026.
- There is no single effective date yet
- The proposed framework would commence in stages through orders after final publication.
- The OPC supports several safeguards
- The submission welcomes secure consumer direction, breach reporting to the Bank of Canada and multi-factor authentication.
- The OPC seeks stronger detail and assurance
- Recommendations address specific data elements, accreditation evidence, complaint procedures, technical-standard evidence, consumer dashboards and sensitivity-based safeguards.
- Public availability should not erase privacy expectations
- The OPC recommends narrowing the consent exception so it does not cover information where a consumer retains a reasonable expectation of privacy.
Global relevance — portable financial data requires portable accountability
Why this matters for global organisations
Open-data ecosystems redistribute sensitive information across institutions, platforms and specialist providers. Even where a particular framework does not apply directly, strong implementations need field-level transparency, meaningful consent, sensitivity-based security, verifiable provider assurance, deletion capability and coordinated incident handling.
- Define data scope at field level rather than relying only on broad regulatory or product labels.
- Make consent, renewal, revocation and deletion visible through a usable dashboard.
- Treat publicly accessible information as contextual, not automatically free of privacy expectations.
- Require independent and continuing assurance from providers performing critical data-sharing functions.
- Align breach, complaint and evidence workflows across every organisation that touches the data.
12 actions to start now
- Track the final Consumer-Driven Banking Regulations and Bank of Canada guidance; do not treat the regulator submission as binding text.
- Map the consumer, account, balance, transaction and product data that each proposed service would request, receive, transform, retain or disclose.
- Make data categories specific enough for users, control owners and system teams to understand the actual fields involved.
- Design consent records and dashboards showing purpose, data categories, recipients, duration, renewal, revocation and deletion status.
- Separate data shared by consent from any proposed reliance on a publicly available-data exception and document residual privacy expectations.
- Apply sensitivity-based security requirements in addition to checking whether a prescribed control list is technically complete.
- Require multi-factor authentication and test account-recovery, credential-exposure and consent-renewal paths.
- Define controller, participating-entity and accredited third-party responsibilities across consent, authentication, movement, storage and deletion.
- Obtain proportionate independent assurance of provider security, technical-standard implementation and remediation status.
- Build breach workflows covering investigation, regulator reporting, consumer notification, third-party coordination and evidence preservation.
- Prepare complaint procedures, named contacts, escalation routes and records that can be produced to supervisors.
- Retain protected, intelligible compliance records and reassess them after material product, provider, security or data-scope changes.
Evidence worth retaining
- Regulatory-change log linking proposal sections, regulator recommendations, owners and implementation decisions.
- Field-level data inventory for consumer profile, account, balance, transaction and product data.
- Data-flow and role maps covering participating entities, technical providers, subprocessors and oversight contacts.
- Consent screens, dashboard specifications, purpose records, renewal triggers, revocation and deletion tests.
- Assessment of each publicly available-data use, including the individual’s residual privacy expectation.
- Security architecture and control matrix tied to data sensitivity, threat model and technical standards.
- Independent provider assurance, remediation records and evidence of ongoing technical-standard compliance.
- Authentication, account-recovery, credential-exposure and fraud-test results.
- Breach playbooks, notification decision trees, regulator-report templates and exercise records.
- Complaint procedures, named contacts, service levels, outcomes and escalation evidence.
- Five-year electronic record design, protection controls, intelligibility tests and retention schedule.
- Change notices, vendor-change approvals, policy revisions and management attestations.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which exact data fields would be shared under each broad regulatory category?
- Can consumers understand the scope, purpose, recipient and duration before consenting?
- Which entities control consent, authentication, data movement, storage, support and deletion?
- Could a publicly available-data exception capture information that still carries a reasonable privacy expectation?
- Are security controls demonstrably appropriate to the sensitivity and aggregation risk of the data?
- What independent evidence should each accreditation pathway and provider be required to produce?
- Can the organisation detect credential exposure and trigger consent renewal without unnecessary friction?
- How will breach reporting, consumer notification and privacy-law obligations be coordinated?
- Do complaint procedures and dashboards cover every participating entity and outsourced function?
- Which final-text changes would require product redesign rather than a policy update?
Official sources
- Office of the Privacy Commissioner of Canada — news release, 26 August 2026
- Office of the Privacy Commissioner of Canada — submission on Consumer-Driven Banking Regulations
- Canada Gazette — proposed Consumer-Driven Banking Regulations, 27 June 2026
- Department of Justice — Consumer-Driven Banking Act
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.