Proposed Consumer-Driven Banking Regulations
Canada Gazette, Part I, Volume 160, Number 26: Consumer-Driven Banking Regulations
The Department of Finance published proposed regulations to implement the new Consumer-Driven Banking Act, creating an accredited, API-based framework overseen by the Bank of Canada for secure consumer-directed sharing of financial data. The rules set accreditation, security, consent, reporting, registry and national security review requirements, include penalties, and open a 60-day public comment period.
Summary
Summary#
The Canada Gazette published the proposed Consumer-Driven Banking Regulations on June 27, 2026. They are meant to put the new Consumer-Driven Banking Act (royal assent March 2026) into effect and set rules for how people and businesses can share bank data with approved providers under supervision of the Bank of Canada. There is a public comment period of 60 days.
What it does#
- Sets up an accreditation system so only approved firms can join the data‑sharing system. Applicants pay an application fee of $2,500 (adjusted for inflation) and there are ongoing assessment fees.
- Requires security, record‑keeping and incident‑reporting rules for participants. Examples include uptime and performance standards such as 99.5% availability and making 24 months of transaction history available on request.
- Defines what kinds of data are in scope: account identifiers, balances, transactions, product terms and customer profile data for deposit, payment, investment and lending accounts.
- Splits responsibilities and liability: requesters must obtain consent and receive data securely; providers must authenticate the consumer before sharing.
- Creates a public registry of participating entities and accredited third‑party service providers, and requires visible signs (digital/physical) to show an entity is in the framework.
- Introduces national security checks: the Minister of Finance can order reviews and block or impose conditions on accreditation for national security reasons.
- Establishes oversight roles: the Bank of Canada will supervise, a designated technical standards body will set the single technical standard, and an external complaints body (not‑for‑profit) will handle consumer disputes.
- Lays out enforcement tools and penalties. Administrative monetary penalties can be used; maximum penalties are $1,000,000 for individuals and $10,000,000 for entities.
- Notes the proposed ban on screen scraping is not being brought into force immediately; timing and rules for that ban will be decided later.
- Estimates an overall cost of $457.7 million (present value) over 10 years and monetized benefits of $13.2 billion (present value) over 10 years.
Who's affected#
- Banks and other federally regulated financial institutions (some large banks may be mandated to join).
- Provincial financial institutions and credit unions that choose to opt in.
- Fintech companies and other data‑driven service providers that want to request or handle consumer financial data.
- Accredited third‑party service providers that provide technical or consent/authentication services to participants.
- Payment service providers (PSPs) already registered under the Retail Payment Activities Act who may use a streamlined accreditation path.
- Consumers and small businesses who use financial apps today — the document estimates about 9 million Canadians currently use data‑sharing services via screen scraping and could be affected by the shift to the regulated framework.
- The Bank of Canada, the Department of Finance Canada and provincial regulators who will have roles in oversight and coordination.
- Smaller firms: the analysis identifies about 578 small businesses affected, with an average annualized compliance cost estimated at $89,133 per small business.
Why it matters#
- Safer data sharing: the rules are designed to replace insecure practices like screen scraping with an accredited, API‑based system and clearer security and incident rules.
- More competition and new services: by enabling accredited fintechs to access customer‑authorised data, the government expects new tools for budgeting, lending, SME accounting and product switching — estimated monetized benefits of $13.2 billion over 10 years.
- Clearer consumer protections: the proposal spells out consent, data deletion, liability and an external complaints route so consumers have more recourse if something goes wrong.
- Costs and trade‑offs: businesses will face setup and ongoing compliance costs — estimated at $457.7 million (present value) over 10 years — and some of those costs could be passed on indirectly to customers.
- National security and supervision: the rules include screening and review powers aimed at keeping hostile actors out of the payment/data ecosystem.
- Phased rollout and remaining uncertainty: the regulations would be phased in (the government intends the full set to be in force within one year of final Part II publication), and some elements (notably the timing of the screen‑scraping ban) remain to be decided.
Key topics
Source: Canada Gazette