A framework six years in the making finally has draft text
On June 27, 2026, the Department of Finance pre-published draft Consumer-Driven Banking Regulations in the Canada Gazette, Part I — the operational detail underneath the Consumer-Driven Banking Act that Parliament passed to create Canada's open banking system (Canada Gazette, Part I, Vol. 160, No. 26). The 60-day comment period runs to August 26, 2026. Once finalized, the Bank of Canada becomes the framework's supervisor, overseeing which banks, credit unions, fintechs, and third-party providers may plug into a system where consumers can direct their own account, balance, and transaction data to a service of their choosing (Bank of Canada, Consumer-Driven Banking).
The headline mechanism worth defending is the accreditation ladder. Full accreditation is expensive and slow by design — a $2,500 application fee, mandatory Canadian corporate presence, integrity screening of key personnel, insurance covering data-management risk, and demonstrated compliance with technical and security standards. But for payment service providers already registered under the Retail Payment Activities Act — a list that already includes Koho, Venn, and Wealthsimple among roughly 300 registrants — the regulations create a streamlined path: reaffirm existing organizational information, show technical-standard compliance, and demonstrate consent-management processes, rather than restart the vetting process from zero (BetaKit).
The case for the mandate, stated fairly
Regulators didn't invent this problem. Canadian fintechs today largely access bank data through screen-scraping — apps that log into a customer's online banking with their password and parse the HTML, a practice that spreads credentials across dozens of third parties and gives consumers no real way to revoke access selectively. A standardized, API-based data-sharing mandate with defined security floors — 99.5% monthly uptime, breach reporting "as soon as feasible," mandatory notification when a breach creates meaningful consumer harm, and a 12-month cap on consent before renewal — is a legitimate response to that risk, not regulatory overreach for its own sake (Bennett Jones). Banks have had little commercial incentive to build clean, permissioned APIs for competitors; a legislative mandate forces the collective-action problem to resolve. Abraham Tachjian, Canada's former open banking lead, said he was "pleasantly surprised" by how far the scope reaches — covering deposit, payment, investment, and lending products — calling it closer to open finance than narrow open banking (per BetaKit's reporting).
Where the design still falls short of proportionate
The RPAA carve-out is the correct instinct: don't force a fintech to prove twice what it already proved to the Bank of Canada under a different statute. That's exactly the kind of regulatory non-duplication this publication has argued for elsewhere. But the industry association FDATA pushed for something further — a "sponsored" accreditation model letting larger, already-accredited players take on regulatory responsibility for smaller entrants riding on their infrastructure, similar to how payment facilitators absorb compliance for sub-merchants. Finance left that out of the draft (per BetaKit). Without it, a small budgeting app or a niche lender still faces the full $2,500 application fee plus an annual assessment ranging from $10,000 to $150,000 depending on asset size, on top of five-year record retention and mandatory participation signage — a fixed compliance cost that a well-capitalized fintech absorbs painlessly and a two-person startup may not.
The bigger problem is timing, not text. The regulations state some obligations take effect within a year of finalization but commit to no actual launch date. For an industry that has spent years building around informal screen-scraping arrangements because there was no legal alternative, an open-ended "sometime after finalization, itself unscheduled" runway makes investment planning difficult. Canada is not the first mover here — comparable mandates in other G7 markets have been live for years — so the credibility cost of another slip compounds each time it happens.
What proportionate would look like
The enforcement backstop — administrative penalties up to $10 million for entities and $1 million for individuals — is calibrated correctly for a data-sharing regime handling financial account information; it should bite hard enough to matter for a systemically important bank while the streamlined RPAA track keeps entry costs sane for the fintechs actually building products on top of the data. The fix Finance should take from this consultation isn't to soften the security bar. It's to adopt something like FDATA's sponsorship model for genuinely small entrants, and — more urgently — commit to a hard implementation date once the rule is finalized, rather than leaving "within one year" open-ended. A framework this well-scoped on substance shouldn't be undermined by ambiguity on when it actually starts.
The accreditation architecture is the right call. The absence of a launch date is the flaw worth fixing before the comment window closes on August 26.