Canada's Department of Finance pre-published the draft Consumer-Driven Banking Regulations in the Canada Gazette, Part I on June 27, 2026, opening a 60-day comment window that closes August 26, 2026. The regulations are the first detailed operating rules for the Consumer-Driven Banking Act (CDBA) — legislation with an unusually tangled history. A version first received royal assent in June 2024 as part of that year's budget bill, but its core provisions were never brought into force. It was repealed and replaced by Division 9 of Bill C-15, the Budget 2025 Implementation Act, No. 1, which received royal assent on March 26, 2026. The rewrite handed primary supervision to the Bank of Canada, which now replaces the Financial Consumer Agency of Canada as the framework's regulator — leveraging the oversight machinery the Bank already built for retail payment service providers under the Retail Payment Activities Act.
What the Draft Actually Requires
The regulations set out accreditation, security, consent, liability, and fee rules for any firm that wants to receive Canadians' financial data through the open-banking system. Four pathways exist: federally and provincially regulated financial institutions, RPAA-registered payment service providers (streamlined review), other fintechs (full non-streamlined review), and accredited third-party service providers. Every applicant pays the same one-time $2,500 accreditation fee, adjusted for inflation and rounded to the nearest $100 annually. On top of that, participating entities owe tiered annual assessment fees ranging from $10,000 to $150,000 depending on asset size, accredited third-party providers pay a flat $10,000, and the external complaints body is funded by a $50,000 fee. Data-sharing endpoints must hit 99.5% monthly uptime outside planned outages, consent and revocation flows must be "clear, simple, and not misleading," security controls must include multi-factor authentication, and entities must retain at least 24 months of consumer data on request. Violations carry penalties up to C$1 million for an individual and C$10 million for a participating entity or accredited third-party provider.
The Case for Caution, Stated Fairly
There's a real argument for a strict baseline here. Canada's fintech sector has operated for years on screen-scraping — apps asking users to hand over banking passwords so software can log in and pull transaction data — a practice with no standardized security floor and a documented fraud surface. A Bank of Canada-run accreditation regime with mandatory MFA, breach reporting, and a public registry of who's authorized to touch consumer financial data is a defensible response to that risk, and Canada gets the advantage of watching the UK's and Australia's earlier open-banking rollouts before finalizing its own. Consumer trust is also a precondition for adoption: if the first wave of accredited apps leaks data or gets breached, the whole model loses credibility before it has a chance to generate competitive pressure on the incumbent banks.
Where the Uniform Price Tag Misleads
The problem is that the $2,500 fee is the same number attached to two very different processes. A bank or an RPAA-registered payment provider clears a streamlined review that largely defers to compliance work it has already done for other regulators. A standalone fintech with no RPAA registration faces the full non-streamlined track: proof of Canadian presence, insurance coverage, baseline security audits, and an "integrity and good character" assessment of key personnel — a materially heavier lift that the flat fee doesn't reflect. Steve Boms, executive director of FDATA, framed the stakes plainly, saying the goal should be "ensuring that small fintechs can offer their services, products, and tools to Canadians just as larger fintechs can," because "a more vibrant, competitive ecosystem benefits everyone, especially the consumers and small businesses who will use the new system." The CDBA's stated purpose includes promoting financial-sector competition; a regime that charges an early-stage fintech the same nominal fee as a bank while demanding a much costlier compliance file to get there risks doing the opposite — quietly favoring firms that can already absorb legal and audit costs, and pricing out the smaller players open banking was supposed to let in.
The Numbers Behind the Bet
The government's own cost-benefit case, cited in regulatory coverage of the filing, estimates roughly $457.7 million in implementation costs against $13.2 billion in projected benefits over ten years — a favorable ratio on paper. But that return depends on who actually gets accredited. If the non-streamlined pathway's real costs (insurance, audits, personnel vetting) discourage smaller applicants during the 60-day comment period, the benefit case shrinks to whatever a handful of banks and well-capitalized fintechs can capture, not the broader competitive market the Act promises.
The Fix Is Available Before Final Publication
None of this requires scrapping the accreditation model — the security and consent baselines are sound and worth keeping. What the comment period should produce is genuine risk-based tiering within the fee and documentation requirements themselves, not just in review speed: lighter insurance and audit thresholds for early-stage applicants scaled to the data volumes they'll actually handle, rather than a single non-streamlined bar applied uniformly to every non-bank. The Bank of Canada has until the regulations are finalized to close that gap. If it doesn't, Canada will have built a legally competitive open-banking market that is, in practice, closed to most of the fintechs it was designed to admit.