Consumer-Driven Banking Canada

Security & Privacy

Learn how Canada’s Consumer-Driven Banking Framework is designed to support secure financial data sharing, meaningful consent, responsible data use and strong consumer protection.

Official legislative source: Consumer-Driven Banking Act
Framework foundation

Security and privacy by design

Consumer-Driven Banking is intended to provide a regulated alternative to sharing online-banking credentials with unregulated services. Data sharing takes place between participating entities when authorized by the consumer.

Protection

Secure data sharing

Financial data is shared through controlled technology connections designed to reduce the need for consumers to disclose their banking passwords to third parties.

Authorization

Consumer consent

Consumers decide whether to share their data, which participating organization may receive it and the purposes for which it is shared.

Oversight

Supervised participation

Participating entities operate within a framework overseen by the Bank of Canada and must continue meeting applicable requirements.

Transparency

Clear data practices

Consumers should receive understandable information about the data being requested, why it is needed and how it will be used.

Consumer direction

How secure, authorized sharing works

A consumer-directed data-sharing journey should clearly identify the organizations involved, the requested information and the consumer’s choices.

1

Choose a service

The consumer selects a participating application or financial service they want to use.

2

Review the request

The consumer reviews which information is requested, the purpose of sharing and the organizations involved.

3

Provide authorization

The consumer authorizes the request using the appropriate consent and authentication process.

4

Data is shared

The participating entities exchange the approved data through the framework’s technical connection.

5

Manage or withdraw

The consumer can review the authorization and withdraw it through the available consent-management process.

Responsible data use

Core privacy principles

Canadian privacy guidance emphasizes accountability, meaningful consent, limited collection, appropriate safeguards, transparency and individual access.

8 principles
01

Accountability

An organization remains responsible for personal information under its control and should establish clear ownership of its privacy obligations.

02

Identified purposes

The reason for collecting and using information should be identified before or when the information is collected.

03

Meaningful consent

People should understand the nature, purpose and potential consequences of the data collection, use or disclosure.

04

Limited collection

Organizations should collect only the information that is reasonably necessary for the identified purpose.

05

Limited use and retention

Information should be used only for authorized purposes and retained only as long as reasonably required.

06

Appropriate safeguards

Safeguards should reflect the sensitivity of the data and protect it from loss, theft and unauthorized access or use.

07

Openness

Organizations should make information about their privacy policies and information-management practices available.

08

Access and correction

Individuals should have a process to request access to their information and challenge its accuracy where applicable.

Learn about Canadian privacy principles

The Office of the Privacy Commissioner of Canada provides guidance on PIPEDA’s fair information principles and the protection of personal information.

View privacy principles
Organizational readiness

Security capabilities for participants

Organizations handling financial data need layered safeguards that address technology, people, processes and external dependencies.

Identity and access

Strong authentication

Authentication controls help verify that the consumer and participating organizations are who they claim to be before sensitive information is accessed or shared.

  • Strong consumer authentication
  • Multi-factor authentication where appropriate
  • Secure account recovery
  • Role-based access controls
  • Privileged-access management

These are educational examples of common security capabilities. They are not a substitute for the official supervisory framework, regulations or organization-specific risk assessments.

Breach and incident management

Responding when something goes wrong

Strong incident response combines rapid containment, investigation, communication, recovery and lessons learned.

1
Detect

Identify the incident

Confirm suspicious activity, determine which services and information may be affected and activate the appropriate response process.

2
Contain

Limit further impact

Isolate affected systems, revoke compromised access and take practical steps to prevent further unauthorized activity.

3
Assess

Understand what happened

Investigate the cause, the information involved, the affected people and the potential consequences.

4
Notify

Meet reporting obligations

Determine whether notifications to consumers, regulators, law enforcement or participating partners are required.

5
Recover

Restore services safely

Correct the underlying issue, restore systems, monitor for recurring activity and communicate recovery progress.

6
Improve

Learn from the incident

Document lessons learned and improve policies, technology, training and controls to reduce future risk.

Privacy-breach responsibilities

Under PIPEDA, organizations may be required to report a breach that creates a real risk of significant harm, notify affected individuals and retain records of security safeguard breaches.

View OPC breach guidance
Protect yourself

Security tips for consumers

Consumers should remain alert when connecting financial accounts or responding to messages that request sensitive information.

Verify the provider

Confirm that the service and organization are legitimate before connecting an account or sharing information.

Review the request

Read which data is requested, how it will be used and how long the authorization will remain active.

Protect credentials

Do not provide online-banking passwords through unexpected emails, text messages or unfamiliar websites.

Use strong authentication

Enable multi-factor authentication and use unique, difficult-to-guess credentials for important accounts.

Monitor accounts

Review account activity and investigate unfamiliar transactions, access notifications or authorization changes.

Watch for urgency

Be cautious of messages that pressure you to act immediately, reveal information or click an unfamiliar link.

Review authorizations

Periodically review connected applications and remove access that is no longer needed.

Report concerns

Contact your financial institution promptly if banking information or account access may have been compromised.

Trusted information

Official security and privacy resources

Consult these primary Canadian sources for legislation, regulatory information, privacy guidance and cyber-security advice.

6 official sources
Proposed
Canada Gazette

Proposed Regulations

Review proposed requirements involving security, authentication, consent management, reporting and record keeping.

View the regulations
Oversight
Bank of Canada

Regulatory Oversight

Follow the Bank of Canada’s work to administer the framework and supervise participating organizations.

Visit the Bank of Canada
Privacy
Privacy Commissioner of Canada

PIPEDA Privacy Principles

Learn about accountability, consent, limiting collection, safeguards, openness, access and other privacy principles.

Explore privacy principles
Breaches
Privacy Commissioner of Canada

Privacy Breach Guidance

Find guidance for assessing, reporting, recording and responding to breaches involving personal information.

View breach guidance
Cyber security
Canadian Centre for Cyber Security

Cyber-Security Guidance

Access Canadian guidance covering phishing, authentication, identity protection, secure websites and cyber threats.

Explore cyber guidance
Common questions

Security and privacy FAQ

Search the questions below for plain-language information about consent, data protection and consumer security.

Showing all questions
01 Is Consumer-Driven Banking designed to be secure?

Yes. The purpose of the Consumer-Driven Banking Act includes ensuring that data sharing among participating entities is safe and secure. Detailed requirements are established through legislation, regulations, technical standards and regulatory oversight.

Consult the official Act
02 Will I give a fintech my online-banking password?

The regulated framework is intended to support secure data sharing without requiring consumers to disclose their banking credentials directly to the service receiving their financial data.

03 Can I withdraw my consent?

The framework includes consent-management and withdrawal requirements. Consumers should be provided with a clear process for reviewing and withdrawing authorizations.

04 Can a provider request all of my financial data?

Requests should identify the data needed and the purpose for which it will be used. Canadian privacy principles emphasize limiting collection to information that is necessary for an identified purpose.

Review PIPEDA principles
05 What happens if there is a data breach?

The organization should contain and investigate the incident, assess the potential harm and meet applicable reporting, notification and record-keeping requirements.

View official breach guidance
06 How will I know whether a provider is approved?

The Act provides for a registry of participating entities. Consumers should use official information and confirm a provider’s status before authorizing data sharing.

07 Who oversees security and privacy?

The Bank of Canada administers and supervises the Consumer-Driven Banking Framework. Privacy obligations may also arise under PIPEDA or applicable provincial privacy legislation, overseen by the relevant privacy authority.

08 What is an API and why is it more secure?

An API is a controlled technology connection that allows systems to exchange approved information. Properly implemented APIs can restrict what information is shared, authenticate the parties involved and produce auditable activity records.

09 Will Consumer-Driven Banking eliminate scams?

No system eliminates every risk. Consumers should still be alert for phishing, impersonation, suspicious links and requests for banking passwords or verification codes.

Review Canadian phishing guidance