Security & Privacy
Learn how Canada’s Consumer-Driven Banking Framework is designed to support secure financial data sharing, meaningful consent, responsible data use and strong consumer protection.
Security and privacy by design
Consumer-Driven Banking is intended to provide a regulated alternative to sharing online-banking credentials with unregulated services. Data sharing takes place between participating entities when authorized by the consumer.
Secure data sharing
Financial data is shared through controlled technology connections designed to reduce the need for consumers to disclose their banking passwords to third parties.
Consumer consent
Consumers decide whether to share their data, which participating organization may receive it and the purposes for which it is shared.
Supervised participation
Participating entities operate within a framework overseen by the Bank of Canada and must continue meeting applicable requirements.
Clear data practices
Consumers should receive understandable information about the data being requested, why it is needed and how it will be used.
How secure, authorized sharing works
A consumer-directed data-sharing journey should clearly identify the organizations involved, the requested information and the consumer’s choices.
Choose a service
The consumer selects a participating application or financial service they want to use.
Review the request
The consumer reviews which information is requested, the purpose of sharing and the organizations involved.
Provide authorization
The consumer authorizes the request using the appropriate consent and authentication process.
Data is shared
The participating entities exchange the approved data through the framework’s technical connection.
Manage or withdraw
The consumer can review the authorization and withdraw it through the available consent-management process.
Core privacy principles
Canadian privacy guidance emphasizes accountability, meaningful consent, limited collection, appropriate safeguards, transparency and individual access.
Accountability
An organization remains responsible for personal information under its control and should establish clear ownership of its privacy obligations.
Identified purposes
The reason for collecting and using information should be identified before or when the information is collected.
Meaningful consent
People should understand the nature, purpose and potential consequences of the data collection, use or disclosure.
Limited collection
Organizations should collect only the information that is reasonably necessary for the identified purpose.
Limited use and retention
Information should be used only for authorized purposes and retained only as long as reasonably required.
Appropriate safeguards
Safeguards should reflect the sensitivity of the data and protect it from loss, theft and unauthorized access or use.
Openness
Organizations should make information about their privacy policies and information-management practices available.
Access and correction
Individuals should have a process to request access to their information and challenge its accuracy where applicable.
Learn about Canadian privacy principles
The Office of the Privacy Commissioner of Canada provides guidance on PIPEDA’s fair information principles and the protection of personal information.
Security capabilities for participants
Organizations handling financial data need layered safeguards that address technology, people, processes and external dependencies.
Strong authentication
Authentication controls help verify that the consumer and participating organizations are who they claim to be before sensitive information is accessed or shared.
- Strong consumer authentication
- Multi-factor authentication where appropriate
- Secure account recovery
- Role-based access controls
- Privileged-access management
Protecting sensitive data
Financial and personal data should be protected throughout its lifecycle, including during transmission, processing, storage and deletion.
- Encryption in transit and at rest
- Secure key and secret management
- Data classification
- Data minimization
- Secure retention and disposal
Continuous monitoring
Monitoring helps organizations identify unusual behaviour, unauthorized access, fraud indicators and operational issues.
- Security-event logging
- Fraud and anomaly detection
- API activity monitoring
- Alert investigation
- Audit trails and reporting
Operational resilience
Participating organizations should be capable of maintaining important services and recovering safely when disruptions occur.
- Business continuity planning
- Disaster recovery
- Availability and capacity monitoring
- Backup and restoration testing
- Incident exercises
Third-party risk management
Organizations remain responsible for understanding and managing risks created by technology providers, processors and other external service partners.
- Supplier due diligence
- Security and privacy contract terms
- Ongoing performance monitoring
- Incident-notification requirements
- Exit and transition planning
These are educational examples of common security capabilities. They are not a substitute for the official supervisory framework, regulations or organization-specific risk assessments.
Responding when something goes wrong
Strong incident response combines rapid containment, investigation, communication, recovery and lessons learned.
Identify the incident
Confirm suspicious activity, determine which services and information may be affected and activate the appropriate response process.
Limit further impact
Isolate affected systems, revoke compromised access and take practical steps to prevent further unauthorized activity.
Understand what happened
Investigate the cause, the information involved, the affected people and the potential consequences.
Meet reporting obligations
Determine whether notifications to consumers, regulators, law enforcement or participating partners are required.
Restore services safely
Correct the underlying issue, restore systems, monitor for recurring activity and communicate recovery progress.
Learn from the incident
Document lessons learned and improve policies, technology, training and controls to reduce future risk.
Privacy-breach responsibilities
Under PIPEDA, organizations may be required to report a breach that creates a real risk of significant harm, notify affected individuals and retain records of security safeguard breaches.
Security tips for consumers
Consumers should remain alert when connecting financial accounts or responding to messages that request sensitive information.
Verify the provider
Confirm that the service and organization are legitimate before connecting an account or sharing information.
Review the request
Read which data is requested, how it will be used and how long the authorization will remain active.
Protect credentials
Do not provide online-banking passwords through unexpected emails, text messages or unfamiliar websites.
Use strong authentication
Enable multi-factor authentication and use unique, difficult-to-guess credentials for important accounts.
Monitor accounts
Review account activity and investigate unfamiliar transactions, access notifications or authorization changes.
Watch for urgency
Be cautious of messages that pressure you to act immediately, reveal information or click an unfamiliar link.
Review authorizations
Periodically review connected applications and remove access that is no longer needed.
Report concerns
Contact your financial institution promptly if banking information or account access may have been compromised.
Official security and privacy resources
Consult these primary Canadian sources for legislation, regulatory information, privacy guidance and cyber-security advice.
Consumer-Driven Banking Act
Read the federal legislation establishing the framework, consumer authorization rules, security obligations and participant responsibilities.
Read the ActProposed Regulations
Review proposed requirements involving security, authentication, consent management, reporting and record keeping.
View the regulationsRegulatory Oversight
Follow the Bank of Canada’s work to administer the framework and supervise participating organizations.
Visit the Bank of CanadaPIPEDA Privacy Principles
Learn about accountability, consent, limiting collection, safeguards, openness, access and other privacy principles.
Explore privacy principlesPrivacy Breach Guidance
Find guidance for assessing, reporting, recording and responding to breaches involving personal information.
View breach guidanceCyber-Security Guidance
Access Canadian guidance covering phishing, authentication, identity protection, secure websites and cyber threats.
Explore cyber guidanceSecurity and privacy FAQ
Search the questions below for plain-language information about consent, data protection and consumer security.
01 Is Consumer-Driven Banking designed to be secure?
Yes. The purpose of the Consumer-Driven Banking Act includes ensuring that data sharing among participating entities is safe and secure. Detailed requirements are established through legislation, regulations, technical standards and regulatory oversight.
Consult the official Act02 Will I give a fintech my online-banking password?
The regulated framework is intended to support secure data sharing without requiring consumers to disclose their banking credentials directly to the service receiving their financial data.
03 Can I withdraw my consent?
The framework includes consent-management and withdrawal requirements. Consumers should be provided with a clear process for reviewing and withdrawing authorizations.
04 Can a provider request all of my financial data?
Requests should identify the data needed and the purpose for which it will be used. Canadian privacy principles emphasize limiting collection to information that is necessary for an identified purpose.
Review PIPEDA principles05 What happens if there is a data breach?
The organization should contain and investigate the incident, assess the potential harm and meet applicable reporting, notification and record-keeping requirements.
View official breach guidance06 How will I know whether a provider is approved?
The Act provides for a registry of participating entities. Consumers should use official information and confirm a provider’s status before authorizing data sharing.
07 Who oversees security and privacy?
The Bank of Canada administers and supervises the Consumer-Driven Banking Framework. Privacy obligations may also arise under PIPEDA or applicable provincial privacy legislation, overseen by the relevant privacy authority.
08 What is an API and why is it more secure?
An API is a controlled technology connection that allows systems to exchange approved information. Properly implemented APIs can restrict what information is shared, authenticate the parties involved and produce auditable activity records.
09 Will Consumer-Driven Banking eliminate scams?
No system eliminates every risk. Consumers should still be alert for phishing, impersonation, suspicious links and requests for banking passwords or verification codes.
Review Canadian phishing guidanceNo questions found
Try another keyword or clear your search.
