Part IIFinal RegulationPublished: November 22, 2023
New Rules for Retail Payment Providers
Retail Payment Activities Regulations: SOR/2023-229
Final regulations establish a Bank of Canada supervisory regime for payment service providers (PSPs). PSPs must register with the Bank, keep written risk‑management and fund‑safeguarding frameworks, report incidents and submit an annual report, and face administrative monetary penalties for violations.
- Published
- November 22, 2023
- Department
- Unavailable
- Section
- TABLE OF PROVISIONS
- Comment deadline
- March 28, 2023
- Effective date
- November 1, 2024
- Publication part
- Part II
Summary
Summary#
The Canada Gazette published the final Retail Payment Activities Regulations under the Retail Payment Activities Act. The rules set new oversight for companies that run payment services (like payment processors and digital wallets): they must register with the Bank of Canada, safeguard customer funds, manage operational risks and report incidents and yearly activity.
What it does#
- Requires a written risk management and incident-response plan that covers availability, integrity and confidentiality of payment systems, testing, reviews and oversight by a senior officer.
- Requires companies that hold customer (end‑user) funds to use approved accounts or insurance/guarantees and to keep a written safeguarding‑of‑funds framework and daily ledgers.
- Sets rules for incident reporting:
- notice to the Bank of Canada using its electronic system, and
- notice to materially affected individuals or entities (by email or website post if contact info is missing).
- Requires an annual report from each registered payment service provider by March 31 for the previous calendar year, with details on risk frameworks, funds held, transaction volumes and other metrics.
- Creates a registration process with a one‑time fee of $2,500 (adjusted for inflation after the first year) and information requirements about organization, third‑party service providers, and where data is stored.
- Adds national‑security review steps for registrations (including prescribed review windows of 60 days for initial review and 180 days for a formal review).
- Establishes record‑keeping and retention (records intelligible to the Bank, retained for 5 years after they stop showing compliance) and protections for supervisory information.
- Authorizes administrative monetary penalties (AMPs): up to $1,000,000 for a serious violation and up to $10,000,000 for a very serious violation; some information‑provision breaches carry daily penalties of $500 for the first 30 days.
- Requires independent reviews of key frameworks at least once every 3 years, and more frequent internal reviews and testing as set out in the rules.
- Excludes certain activities and entities (for example, securities transactions done under Canadian securities law and the SWIFT network).
Who's affected#
- Primary: payment service providers (PSPs) such as payment processors, digital wallets and similar businesses that perform payment functions for end users in Canada — including foreign PSPs that serve Canadians.
- Also affected: third‑party service providers, agents and mandataries used by PSPs; registered financial institutions that provide accounts or insurance to PSPs; the Bank of Canada and the Department of Finance (for supervision and national security reviews).
- Not covered: federally or provincially prudentially regulated financial institutions (for their regulated activities). If it is unclear whether a particular business is in‑scope, the Bank of Canada’s guidance is intended to clarify the boundary.
Why it matters#
- Consumer protection: the rules are meant to reduce the risk that people or businesses lose access to their money if a payment company fails or has a major outage, and to speed recovery when incidents happen.
- System reliability and security: PSPs must prepare for and report outages and cyber incidents, which aims to make everyday payments more reliable.
- Costs and oversight: the government estimates the regulations will cost the industry about $170.6 million (present value) over 10 years, or about $24.3 million per year (present value). They estimate about 2,500 PSPs could be affected. That may mean higher compliance costs for some small providers, but the government says the rules should increase confidence in payment services.
- National security: the Minister of Finance gains a clearer process to review and, if needed, block or impose conditions on PSP registrations where security concerns are identified.
- Timing: the rules and the Act are being phased in so firms have time to register and comply; key dates set by the government include registration-related steps in November 2024 and the operational safeguards coming into force in September 2025 (the Bank of Canada will publish guidance ahead of these dates).
Key topics
Retail Payment Activities ActRetail Payment Activities RegulationsBank of CanadaDepartment of Financepayment service providersPSPrisk management and incident response frameworksafeguarding-of-funds frameworkend-user fundsincident reportingannual reportregistration with the Bank of Canadanational security reviewSWIFTadministrative monetary penalties
Source: Canada Gazette