
14 August 2026 • 7 minute read
Preparing for open banking: key takeaways from Canada’s draft Consumer-Driven Banking Regulations
On June 27, 2026, the Department of Finance released the proposed Consumer-Driven Banking Regulations (the Proposed Regulations), which provide the implementation framework for the Consumer Driven Banking Act (the Act).
Consumer-driven banking, also referred to as “open banking,” permits individuals and businesses to securely share their financial information with authorized third-party providers through application programming interfaces (APIs). In April 2026, we published an article which summarized how the new framework allows individuals to share their financial data with financial technology companies (such as fintechs) of their choice. The new framework will be overseen by the Bank of Canada (the Bank).
How entities become accredited
Only entities that meet certain requirements in accordance with the Proposed Regulations can participate in the Act’s framework. There are four pathways of accreditation, specific to different entities:
- Non- streamlined accreditation;
- Streamlined accreditation for entities registered under the Retail Payment Activities Act (RPAA);
- Accreditation for federal and provincial financial institutions; and
- Accreditation for third-party service providers.
The Act gives the Minister of Finance the authority to mandate the participation of certain banks in the framework. Banks that are mandated to participate are not subject to the accreditation process. Fintechs and other non-bank entities seeking accreditation must:
- Have a place of business in Canada;
- Have insurance or a comparable guarantee that covers open banking risks;
- Submit organization and operation information;
- Implement an integrity and good character policy for key personnel; and
- Comply with applicable technical standards.
Regardless of accreditation pathway, all applicants must pay a prescribed one-time accreditation fee to the Bank of $2,500, subject to annual adjustment. Participating entities would also incur ongoing annual assessment fees determined by their total asset value, ranging from $10,000 (assets under $1 billion) to $150,000 (assets of $1 trillion or more). Accredited third-party service providers (ATPSPs) pay a fixed annual fee of $10,000.
The Bank will have the authority to deny, suspend, or revoke the accreditation status of any participating entity or third-party service provider. Violations of the Act or the Proposed Regulations may result in an administrative monetary penalty of up to $1 million for individuals and up to $10 million for participating entities or ATPSPs. The Proposed Regulations provide a mechanism for appeal to the federal court.
Takeaways for banks
The banks mandated to participate remain subject to the “common rules” in the Proposed Regulations, which establish obligations related to privacy, consent, liability, security, national security, and integrity.
The Proposed Regulations require data providers to employ identity management and access control mechanisms. Once a consumer has authorized a participating entity to request data on their behalf, the data provider must authenticate the consumer before sharing that data. This responsibility is divided between the data requester and the data provider.
Reauthentication is also required in situations where consent renewal is obliged.
Data regulations
The Proposed Regulations outline the type of consumer data subject to the Act’s framework. Participating entities must share consumer-authorized in-scope data, including data related to deposit accounts, payment products, investment accounts, and lending accounts. Participating entities may not impose a charge for doing so, nor for obtaining, renewing, or withdrawing consent.
Proposed account data for in-scope data sharing would include the following:
- Information identifying the account(s) held by the consumer;
- Contractual terms and conditions applicable to the consumer’s account;
- Balance data;
- Transaction data; and
- Information related to the products and services that are offered to the consumer.
The Proposed Regulations require participating entities to maintain availability of their APIs 99.5% per month (excluding planned outages). Response times must also be consistent with acceptable, international standards. Participating entities are also required to make available a minimum of 24 months of consumer data upon request.
What is required of participating entities
- Display of Sign: Participating entities must display a Bank-prescribed visual identifier or sign on physical and digital properties and must not use it in a misleading manner regarding their accreditation status.
- Notice of Change: Participating entities must notify the Bank of changes that would impact their accreditation outcome, including changes to contact information, organization structure, insurance coverage, key personnel, or compliance status. Changes with more immediate impacts must be reported to the Bank as soon as feasible, while all other changes must be reported within 30 days.
- Record Keeping: Participating entities must retain sufficient electronic records to demonstrate compliance with the Act and Proposed Regulations for five years, unless otherwise specified. They must protect records from loss, destruction, falsification, inaccuracies, and unauthorized access.
- Security: Security breaches involving consumer data must be reported to the Bank as soon as possible, including the circumstances, timing, and proposed response. If a breach creates a risk of significant harm, the consumer must be notified directly or indirectly, as appropriate. Breach investigations must also be reported through the Bank’s electronic system as soon as feasible.
- Annual Reporting: Participating entities must submit an annual report to the Bank covering data sharing performance and availability, notices of change, significant changes to safeguards or policies, summaries of security breaches, continued compliance with technical standards and safeguards, and financial performance metrics for risk-based supervision.
- Consent: The Proposed Regulations expand on and clarify consent obligations.
- Use of Data: The Proposed Regulations allow limited exceptions for using consumer data for purposes not identified when express consent was obtained, adapting existing Personal Information Protection and Electronic Documents Act (PIPEDA) exemptions to open banking.
- Data Deletion: Consumers may request deletion of their data. Entities need not delete data that has been irreversibly anonymized, and may refuse or delay deletion where a time-bound legal requirement applies. In that case, the entity must provide written reasons and state when deletion will occur, without requiring further action from the consumer.
- Record of Consent and Consent Renewal: Participating entities must keep and provide records of express consent to the Bank. The Proposed Regulations also identify exceptional circumstances requiring consent renewal outside the normal consent period of up to 12 months.
Compliance with the Proposed Regulations does not guarantee compliance with privacy legislation, such as PIPEDA. Participating entities will need to ensure that they are compliant with both applicable privacy legislation and the Proposed Regulations.
Implementation timelines
The Proposed Regulations are subject to a 60-day consultation period ending August 26, 2026. Stakeholders may provide feedback through the comment feature on the Canada Gazette, Part I website.
Implementation would follow a staggered approach, starting with the accreditation requirements first. The common rules and assessment fees will follow at later dates. Implementation is intended to occur within one year of final publication of the Proposed Regulations in the Canada Gazette, Part II.
This publication is a general overview of certain legal developments and should not be relied upon as legal advice. Contact a member of our Financial Services or Compliance team if you have any questions or need further assistance regarding the Proposed Regulations.