Article
CBA Submission on Bill C‑15 (Budget 2025 Implementation Act, No. 1) and the Consumer‑Driven Banking Act
Overview
This submission sets out the Canadian Bankers’ Association’s (CBA) views on the proposed Consumer‑Driven Banking Act ("CDBA" or "the Act") under Division 9 of Bill C‑15, the Budget 2025 Implementation Act, No. 1. It is limited to measures that establish or advance the consumer‑driven banking framework ("the framework") and does not address other elements of the Bill.
The CBA and its members are committed to advancing responsible innovation and competition in Canada’s financial services sector within a trusted, stable, and secure financial system. Our industry supports the continued development of a secure, competitive, and consumer-centric data sharing framework. Clear rules, well‑defined roles and responsibilities, and consistent application of common rules for all participating entities will be essential to maintaining consumer confidence and trust in the framework. In particular, we support measures that ensure strong and predictable consumer protection, promote interoperability and efficiency, and enable innovation. Ensuring that liability flows with the data, applying reciprocity across participants, and transitioning away from unsecure practices such as screen scraping will help deliver a secure, modern, and consumer‑centric ecosystem.
Recommendations
Our recommendations set out below are intended to support the effective operation of the framework by leveraging industry expertise, minimizing regulatory duplication, enabling appropriate flexibility, and promoting consistent clear rules across participants and consistent consumer experiences and protections. These recommendations should be considered as regulations and guidance to support the Act are developed.
1. Consent and Authorization
The Act should clearly and consistently allocate responsibility for obtaining and managing consumer consent to the participating entity in the role of a data receiver (data recipient), while responsibility for authenticating the identity of consumers and getting consumer authorization to share data should rest with the participating entity in the role of a data provider (data provider).1 This allocation reflects the functional roles of participants within the framework and should be referenced consistently across the Act, regulations, guidance, and the designated technical standard. This will foster operational clarity for participating entities, maintain a predictable consumer experience, and support alignment between compliance and liability expectations.
As drafted, sections 92 and 93 introduce ambiguity in this allocation. In particular, section 93 may require a data provider to intervene when consent has expired, including by requiring the data provider to request the data recipient to renew the consumer’s express consent. If this approach is supported by forthcoming regulation, this shifts elements of consent management onto the data provider and away from the data recipient who is requesting data to provide a service or product. To ensure consistent consumer experiences, data providers should not be responsible for tracking, prompting, or otherwise managing the renewal of consumer consent within the recipient‑led consumer journey. As drafted, the current approach creates the risk for duplicative and cumbersome consumer experiences. Section 92 also appears to support an obligation on data providers that can only be fulfilled where the data recipient has first supplied necessary‑and accurate‑information as part of the access request.
The Act should be amended, including through the removal of section 93, the introduction of a new section, and an adjustment to section 92, to confirm that responsibility for obtaining, maintaining, and renewing consumer consent rests exclusively with the data recipient, and that data providers are not required to initiate or prompt consent renewal. In certain scenarios where the data provider has been put on notice or has reason to believe that a circumstance that renders the authorization to share data invalid or requires cessation of data sharing (e.g. fraud), we believe section 93 should require the data provider to notify the data recipient that the authorization to share is no longer valid. The data recipient would then be responsible for obtaining new consent if appropriate. This approach aligns with the intended roles of each participant and the policy intent of the Act.
The Act should also explicitly require data recipients to provide the necessary information2 to data providers to enable data providers to perform their authorization functions under section 92, with operational detail to be addressed through regulations or technical standards. Section 92 and regulations should clarify that data providers are responsible for presenting to the consumer (i) the period for which the consumer’s data is to be shared, and (ii) the products and services held by the data provider for which the data provider is authorized to share. This clarification will help to clarify ensure that data providers are not held accountable for matters outside their control, thereby reinforcing the distinct roles and responsibilities of each participant as envisioned in the policy objectives of the Act. (See Appendix below for specific recommendations to the Act).
2. Liability
The CBA and its members support a clear liability framework with clear and consistent rules for data sharing, providing certainty for participating entities and protection for consumers. For this reason, the Act and its corresponding regulations should ensure that liability rules apply predictably throughout the framework, with responsibility clearly anchored to an entity’s control of data at each stage of the data flow, including through a clear regulatory definition of control that can be operationalized.3
Clear and predictable attribution and responsibility ensures that consumers do not need to navigate the complexity of participant relationships. Instead, consumers would benefit from the certainty that each entity is accountable for the data under their control. And this clarity would also promote secure and responsible innovation by ensuring participants understand their obligation as they develop new services and interact with the framework.
3. Regulatory Efficiency
As the framework is operationalized, the Bank of Canada is expected to coordinate with federal departments, provincial regulators, and other government bodies.4 The CBA supports this approach in principle, while noting that its effectiveness will depend on how coordination mechanisms are applied in practice to ensure consistent oversight over all framework participants.
Prioritizing an economically sustainable framework that leverages existing regulatory structures, with proportionate and consistent oversight, will provide participants with the flexibility needed for the framework to evolve while supporting effective implementation. To support this objective, greater clarity is needed to confirm how obligations under the Act are intended to operate alongside existing privacy, prudential, and supervisory regimes in a manner that avoids prescriptive, duplicative, or conflicting obligations and supports consistent oversight of participants.
For example, banks are already subject to a comprehensive complaints-handling regime under the Bank Act that is substantively similar to the complaints management requirements contemplated under the Act. Absent clear alignment, participants could be required to maintain parallel processes addressing the same consumer protection outcomes. Another example is in relation to third‑party risk management where it is important to avoid conflicting obligations for FRFIs who are subject to OSFI’s Guideline B‑10 Third‑Party Risk Management. Given that banks operating under the framework are obligated to meet the expectations under the Act, which would include sharing data with entities that are accredited under the framework, these accredited entities should not be considered as third parties to banks for the purposes of Guideline B‑10 compliance.5
Providing regulatory clarity would reduce uncertainty, support consistent consumer experiences, and avoid overlapping obligations that could otherwise increase implementation and operational challenges. A regulatory framework that is efficient will encourage participation and avoid introducing operational inefficiencies, both of which are essential to adoption and scale.
4. Screen Scraping
We support the Act’s prohibition on screen scraping as an important consumer protection measure, including prohibiting screen scraping as an alternative means of access.6 Allowing screen scraping as a fallback would undermine the integrity of the framework and create an end-run around its safeguards.
The phasing out of screen scraping will improve security for consumers by eliminating data access through credential sharing and enabling modern, standardized, and secure authentication methods. It will also create a stronger foundation for innovative services built on reliable secure channels where consumers have a clear understanding of the data being shared. We further support continued government‑industry collaboration in the development of the regulations contemplated by the Act to ensure that the prohibition is implemented in a manner that delivers consistent and effective consumer protection across the framework, including clarity on scope and application to prevent inconsistent practices as the framework scales.
5. Reciprocity
To empower consumers to share their data with any accredited participant they choose, the CBA recognizes the importance of the principle of reciprocity within the framework. As the framework develops, this principle should be reviewed, particularly to understand how data flows evolve and whether material asymmetries emerge over time. Adhering to the principle of reciprocity in practice will ensure that consumers continue to benefit from robust data sharing and innovative services.
Beyond the statutory framework set out in the Act,7 the Government can reinforce reciprocity through regulation, supervision, and coordination with other regulators. For example, as part of accreditation and ongoing participation, there should be an assessment that participating entities with in‑scope data are subject to corresponding data‑sharing obligations under the framework. Further discussion will be required as the framework and data sharing use cases mature.
6. Technical Standard
The Act appropriately does not prescribe a specific technical standard, instead enabling a technical standard to be developed and maintained outside primary legislation. It also provides for a supervisory role for the Bank of Canada in relation to the technical standards body, including the ability to require changes, while leaving matters of governance, independence, and operational interaction to be further clarified through industry participation within the standards body. We welcome this approach as it preserves flexibility and allows the framework to evolve in line with technological change, while ensuring appropriate oversight and accountability.
As the Government considers the selection of a technical standards body under the Act, we reiterate our support for a principles‑based and market‑driven approach to standards development. Selecting a mature, interoperable and widely adopted technical standard will accelerate ecosystem readiness, reduce transition risks, and help deliver a consistent and seamless consumer experience.
Timely designation of the technical standard and standards body will be critical to enable participants to prepare for implementation, align internal systems, and support operational readiness across the ecosystem. Governance arrangements within the standards body should ensure balanced representation, independence, and transparency, while allowing the standard to evolve in response to technological and market developments.
7. Digital Framework Considerations
Consumer‑driven banking is intended to operate as a digital framework. Requirements that originate from offline environments should therefore be approached with caution. This helps avoid confusion for consumers, particularly as the process of sharing data between participating entities is required to take place through digital means. This is why the proposed provision contemplating oral consent8 may be difficult to operationalize in a digital consent journey and risks requiring participating entities to build processes and frontline capabilities that are not aligned with a consumer‑directed, digital flow.
Similarly, requirements relating to physical signage9 do not reflect how consumers engage with digital financial services and may introduce unnecessary complexity without improving consumer experiences. We note that other key jurisdictions, including the United Kingdom, European Union, and Australia do not require physical signage in their respective open banking frameworks.
Implementation and Other Considerations
Collaboration between industry participants and the Government from the outset will support effective implementation of the framework and help ensure that both participants and consumers, including small business consumers, understand the benefits, rights, and responsibilities associated with securely sharing their data.
Following the successful launch of the initial phase, an effective and consultative approach to expanding the scope of the framework, including the breadth of data, eligible entities, and functionality (e.g. write access), should proceed according to a clear timeline and focus on consumer‑centric use cases.
Ongoing engagement among industry participants, stakeholders, and regulators will be important as the framework evolves, allowing for the identification of operational efficiencies and refinements informed by experience gained through the read access phase and by lessons from other jurisdictions. At every step, it will be critical to maintain strong security and liability foundations to support consumer trust and adoption.
Conclusion
CBA members are steadfast in our longstanding tradition of collaborating in support of government initiatives that advance the interests of Canadians, and we welcome ongoing consultation to support the successful implementation of the framework. We reaffirm our unwavering commitment to partnering with the Government to realize the full potential of consumer‑driven banking, ensuring meaningful benefits for consumers across the country.
Appendix
| Recommendation & Rationale |
Recommended redraft |
|
Section 92: Consumer Authentication
Recommendation
Add an explicit obligation requiring data recipients to provide the information necessary for data providers to perform their functions under subsection 92(1)(b) and 92(1)(c).
Adjust subsection 92(1)(b) and 92(1)(c) to focus the obligation on data providers to confirm the period that will be shared and to confirm the products and services that the data provider is authorizing to share with the consumer.
Rationale
This recommendation is intended to ensure that subsection 92(1)(b) and (c) operate only to support the data provider’s confirmation of (i) the products and services held by the consumer with the data provider in respect of which data will be shared, and (ii) the period for which the consumer’s data will be shared, based on information supplied by the requesting participating entity.
It is not intended to require the data provider to validate that express consent was obtained by the requesting participating entity, or to confirm the requesting entity’s products or services.
The proposed new section preserves the allocation of responsibilities under the framework, whereby data recipients obtain express consent and data providers authenticate the consumer and authorize disclosure.
|
Proposed new section:
A participating entity that requests that another participating entity provides it with a consumer’s data must provide the other participating entity with the information necessary to enable it to perform its functions under subsection 92(1)(b) and 92(1)(c).
Proposed adjustment to section 92:
Authentication requirements
92 (1) Before providing a consumer’s data to another participating entity, and subject to regulation, a participating entity must confirm the information in 92(1)(a) with the consumer and present the information in 92(1)(b) and 92(1)(c) to the consumer
- the consumer’s authentication information;
- the period for which the consumer’s data is to be provided
express consent is valid; and
- the products and services held by the participating entity providing the consumer’s data in respect of which the data is to be provided.
(2) A participating entity must not, as a condition of providing a consumer’s data to another participating entity, (a) require the consumer to consent to being provided with a product or service; or (b) require the consumer to consent to the participating entity receiving their data from the other participating entity.
Proposed consequential amendment (Section 95(a)(ii)): Amend paragraph 95(a)(ii) as follows: (ii) the period for which the consumer’s consent to the sharing of their data is valid data is being shared.
This is to align dashboard terminology with the proposed shift in sections 92 and 93 from consent renewal to data-sharing status and authorization validity.
|
|
Notice of invalid authorization
(Section 93: Renewal of consent)
Recommendation
Replace the obligation for data providers to request consent renewal with an obligation to notify the data recipient that authorization has been withdrawn or is no longer valid.
Rationale
This keeps consent management with the data recipient, while preserving a clear mechanism for the data provider to act when authorization is no longer valid. It reduces duplication in the consumer journey and supports a consistent allocation of responsibilities across the framework.
|
Section 93: Renewal of consent
93. In the circumstances and within the period provided for in the regulations, a participating entity that is providing a consumer’s data to another participating entity must request that the other participating entity renew the consumer’s express consent in accordance with section 87.
Section 93: Notice of invalid authorization
93 In the circumstances and within the period provided for in the regulations, a participating entity that is providing a consumer’s data to another participating entity and has been put on notice or has reason to believe of a circumstance that renders the authorization to share data invalid or requires cessation of data sharing must request that the other participating entity renew the consumer’s express consent in accordance with section 87. notify the other participating entity that the authorization to share the data is no longer valid.
|
1 The Act sets out the core allocation of responsibilities for consumer consent (sections 85 through 91), consumer authentication (section 92(1)(a)), consumer authentication (sections 92(1)(b) and 92(1)(c)) within the framework. Section 93 addresses where a data recipient may need to renew consent (please refer to the Appendix for targeted amendments)
2 For example, section 92(1)(b) requires the data provider confirm the period for which the consumer’s express consent is valid and section 92(1)(c) the products and services in respect of which the data is to be provided.
3 Sections 103 and 104 of the CDBA provide that, subject to limited exceptions for gross negligence or gross fault, consumers are not liable for losses arising from unauthorized access to or use of their data, while participating entities remain responsible for safeguarding data within their control and liable for losses resulting from security breaches, including where activities are performed by third party service providers or affiliates.
4 Sections 4(c), 5, 72, 82(1) and (3), and 124(1) of the proposed Consumer‑Driven Banking Act under Bill C‑15 addresses regulatory coordination and information sharing between regulatory bodies.
5 The policy objective to exclude the use of privately negotiated contracts to ensure obligations meet banks’ expectations in respect of elements which are now expected to be fully covered through the obligations in the Consumer‑Driven Banking framework. However, it is worthwhile reiterating that participating entities remain responsible for the third parties that they use to share data under the framework.
6 Section 171 prohibits the use of an interface or application to access a consumer’s data using the consumer’s authentication information for the purpose of providing a product or service in Canada, with the scope and application of the prohibition to be set out in regulations.
7 Section 76 imposes reciprocal obligations on participants when sending and receiving consumer‑directed financial data.
8 Section 85(1) of the Act requires a participating entity to obtain a consumer’s express consent before requesting that another participating entity provide the consumer’s data. Section 85(3) further provides that where express consent is given orally, the participating entity must immediately confirm that consent in writing. Furthermore, comparable open banking regimes in the European Union, the United Kingdom, and Australia require explicit, documented consent obtained through authenticated digital processes and do not provide a statutory basis for oral consent followed by written confirmation. As such, Canada’s express recognition of oral consent is distinct among peer frameworks.
9 Section 94 of the Act requires a participating entity, in the form specified by the Bank, to prominently display a sign indicating that it is a participating entity, including at each location in Canada at which it offers services in accordance with the Act, and on the home page of each of its websites and on each application through which it offers such services.