Consumer-Driven Banking Regulations
Canada Gazette, Part I, Volume 160, Number 26: Consumer-Driven Banking Regulations
Proposed regulations published June 27, 2026 would implement the Consumer-Driven Banking Act by creating a Bank of Canada–supervised accreditation and API-based data‑sharing framework that replaces screen‑scraping and sets rules on consent, security, breach reporting, liability, and fees. The proposal includes accreditation and assessment fees, national‑security screening by the Minister of Finance, minimum API service standards (99.5% uptime and 24 months of account history), and is open for 60 days of public comment.
- Published
- June 27, 2026
- Department
- Unavailable
- Section
- REGULATORY IMPACT ANALYSIS STATEMENT
- Comment deadline
- August 26, 2026
- Effective date
- Unavailable
- Publication part
- Part I
Summary
Summary#
This is a set of proposed regulations, titled the Consumer-Driven Banking Regulations, published in the Canada Gazette on June 27, 2026 to put the Consumer-Driven Banking Act into practice. The rules would create a government‑supervised system, led by the Bank of Canada, to let people and businesses share their banking data with approved service providers in a more secure way. The department estimates costs of $457.7 million (present value) over 10 years and potential monetized benefits of $13.2 billion (present value) over 10 years.
What it does#
- Sets up an accreditation and oversight system for companies that want to share or receive consumer financial data under the Consumer-Driven Banking Act. Applicants must pay an accreditation fee of $2,500 (adjusted for inflation).
- Makes the Bank of Canada the main supervisor and requires a public registry of participating firms and accredited third‑party service providers.
- Requires clear consent, record‑keeping, breach reporting, and rules about who is liable if data is lost or misused.
- Includes national security checks by the Minister of Finance for applicants and accredited firms (timelines in the proposal include a decision window of 60 days to start a review and a 180‑day review period, both extendable).
- Sets technical and service standards:
- API endpoints must be available 99.5% of the time per month (except planned outages).
- Participating entities must make 24 months of consumer account history available on request.
- Limits initial functionality to “read only” data sharing (no account‑action “write” features in phase one).
- Establishes administrative fees and a tiered annual assessment structure (base fees up to $150,000 for the largest entities).
- Describes enforcement and penalties; maximum administrative penalties are $1,000,000 for individuals and $10,000,000 for entities.
- Proposes a phased coming‑into‑force, with accreditation and some rules first and the full framework intended to be in place within one year of final Part II publication.
- These are proposed regulations and are open for public comment for 60 days after publication.
Who's affected#
- Ordinary consumers and small businesses who want to share banking data with apps or other service providers. About 9 million Canadians currently use data‑sharing services that rely on less secure methods today.
- Large banks and federally regulated financial institutions (some large banks would be mandated to join the system).
- Credit unions, provincial financial institutions and crown corporations that may opt in.
- Fintechs, payment service providers (PSPs) and other companies that want to offer data‑driven products. Accredited third‑party service providers (ATPSPs) that do consent, authentication or data movement work.
- Small businesses: the government estimates about 578 small businesses would be affected by the new administrative and compliance rules.
- The Bank of Canada, the Minister of Finance and other federal bodies that will oversee and apply national security checks.
- A federally designated external complaints body and a technical standards body (to be named) would also be part of the system.
Why it matters#
- Replaces risky “screen scraping” and informal credential‑sharing with a regulated API system. That aims to reduce privacy and security risks for users.
- Could enable new services and make it easier to switch providers, find better deals, improve budgeting and help some people access credit. The government’s central estimate is net economic benefits (monetized) of $13.2 billion over 10 years against estimated costs of $457.7 million (both present value).
- Introduces compliance and tech costs for businesses. Smaller firms could face proportionally larger burdens and new fees, which could be passed on to customers in some cases.
- Adds a national security screening layer. The Minister can block or condition participation for security reasons.
- This is a proposal. It is not law yet. The public can comment during the 60‑day consultation period that follows publication.
Key topics
Source: Canada Gazette