Home Fintech Open Banking in Canada: Where Consumer-Driven Banking Stands Now
Fintech

Open Banking in Canada: Where Consumer-Driven Banking Stands Now

Share
Share

On June 27, 2026, Ottawa published the proposed Consumer-Driven Banking Regulations in the Canada Gazette. It was a dry document, full of uptime percentages and consent rules, and it barely made the evening news. But for the roughly nine million Canadians who, by the government’s own estimate, hand their online banking passwords to budgeting apps and lenders, it was the clearest sign yet that open banking is finally on its way.

Canada has been talking about this for the better part of a decade. The United Kingdom switched on open banking in 2018. Australia, Brazil and others followed. Canada spent years in consultations, advisory committees and interim reports, and the framework changed regulators partway through. Now the law is done, draft rules are out, and the remaining question is mostly about timing.

Here’s what the framework actually does, where it stands in the fall of 2026, how it compares with the U.K. and the U.S., and what it will change for consumers and the fintech startups building on it.

The problem it’s meant to fix

If you’ve ever connected a budgeting app, a tax tool or a lender’s income check to your bank account, you’ve probably used screen scraping. You type your bank username and password into a third-party app, and that app logs in as you to read your transactions.

It works, but it’s a terrible design. You’re sharing your full credentials, which often gives the app far more access than it needs. Your bank can’t tell the difference between you and the app. And sharing your password may affect your protection under your bank’s fraud policies. When the government laid out its plans in Budget 2024, it estimated that about nine million Canadians were sharing credentials this way.

Open banking replaces that with application programming interfaces, or APIs. Instead of handing over a password, you authorize a specific app to receive specific data, for a specific period, through a secure connection your bank controls. You can revoke it. The app never sees your password.

How Canada got here: a short timeline

Canada’s version is officially called “consumer-driven banking,” and its path has been winding. The key steps:

  1. April 2024: Budget 2024 commits to a framework with one national technical standard, mandatory participation for the largest retail banks, and oversight by the Financial Consumer Agency of Canada (FCAC).
  2. June 2024: The first part of the Consumer-Driven Banking Act becomes law through the 2024 budget bill. In early July, the FCAC welcomes its new mandate and gets $1 million for a public awareness campaign.
  3. Fall 2025: Budget 2025 moves oversight from the FCAC to the Bank of Canada and fills in the rest of the framework, including accreditation, liability and a screen-scraping ban. The implementing bill, C-15, is tabled on November 18, 2025.
  4. March 26, 2026: Bill C-15 receives Royal Assent, completing the Consumer-Driven Banking Act.
  5. June 27, 2026: Draft regulations are published for a 60-day comment period ending August 26.

The regulator switch is worth pausing on. Originally, the FCAC, which already supervises banks’ consumer obligations, was going to run the system. Budget 2025 handed the job to the Bank of Canada instead, which also oversees retail payment providers. Forbes reported that the government set aside $19.3 million over two years for the Bank’s new role. The government’s published materials don’t spell out a reason, but putting data sharing and payments under one supervisor makes sense if Canada eventually wants open banking to move money, not just read balances.

What the framework actually requires

Between the Act and the draft regulations, the shape of the system is now fairly clear.

Who has to participate

The largest retail banks must take part, based on a retail volume threshold set by the Minister of Finance. In practice, observers expect that to mean the Big Six: RBC, TD, BMO, Scotiabank, CIBC and National Bank. Credit unions, provincially regulated institutions and fintechs can join voluntarily if they meet the accreditation requirements. The Bank of Canada will run the accreditation process and maintain a public registry of approved participants.

What data is covered

The scope includes deposit accounts, payment products, investment accounts (registered and non-registered) and lending accounts. It does not include “derived” data, meaning the analysis banks create from your raw data, such as internal credit scores or spending categories.

The fine print in the draft rules

The proposed regulations add specific obligations, as summarized by Canadian data company Flinks and law firm commentary:

  • Banks’ data-sharing systems must be available at least 99.5% of the time each month.
  • Consumers can request at least 24 months of transaction history.
  • Consent lasts a maximum of 12 months before it has to be renewed.
  • Participants must keep records for five years.
  • Penalties reach up to $10 million for participating entities.

Who pays when something goes wrong

This is the part consumers should care about most. Under the Act, you aren’t liable for a financial loss caused by sharing your data inside the framework unless you were grossly negligent with your login credentials. Institutions are responsible for breaches of their own security safeguards. And screen scraping becomes an offence once the framework is fully operational.

So when does it launch?

Here’s the honest answer: not yet, and nobody has committed to a firm date.

In March 2026, the Bank of Canada said it would be “premature and ill-advised” to set a launch date before the full scope of the work was understood, Open Banking Tracker reported. A summary of the Bank’s July 2026 advisory committee meeting gives the clearest picture so far:

  • Final regulations are targeted for late 2026 or early 2027.
  • Obligations are expected to start roughly a year after that, beginning with deposit and payment accounts.
  • Lending and investment accounts follow in later phases, over a timeline that could stretch 18 months or more.
  • The technical standards body, which will set the actual API specifications, still hadn’t been named as of that meeting. An earlier Bank of Canada planning note had expected that decision in spring 2026.

Read together, that points to banks being required to share basic account data sometime in 2027 or 2028, with the full scope arriving later. “Write access,” which would let apps initiate payments or switch accounts on your behalf, is a second phase. Budget 2025 committed to 12 to 18 months of policy work on it, and industry observers link its timing to Payments Canada’s Real-Time Rail, a new instant payment system whose own launch timing remains uncertain.

How Canada compares with the U.K. and the U.S.

United KingdomUnited StatesCanada
Legal basisCompetition order covering the nine largest banksCFPB rule under section 1033 of Dodd-FrankConsumer-Driven Banking Act
Live sinceJanuary 2018Rule finalized October 2024; compliance stayedNot yet; rules in draft
PaymentsYes, including recurring paymentsData access onlyPlanned for a second phase
OversightImplemented through Open Banking LimitedCFPBBank of Canada

The U.K.: proof it can scale

The British system started in January 2018 with nine big banks forced to open up by a competition ruling. By July 2025 it had 15.16 million users, nearly one in three adults. In July 2026, Open Banking Limited said the system had passed one billion payments and 100 billion API calls. In June 2026 alone there were about 40 million open banking payments, including 7.7 million variable recurring payments, a feature that lets you authorize a merchant to pull flexible amounts within limits you set.

The lesson from the U.K. is that payments, not data, are where the real consumer value showed up. Paying a tax bill or topping up an account directly from your bank, without a card, is the use case that took off.

The U.S.: stuck in court

The American story is a cautionary one. The Consumer Financial Protection Bureau finalized its personal financial data rights rule in October 2024, with the largest institutions originally due to comply by April 1, 2026. Banks sued. In August 2025 the CFPB said it would reconsider the rule, including whether banks should be allowed to charge fees for data access. On October 29, 2025, a federal court in Kentucky stayed the compliance dates. The CFPB’s 2026 regulatory agenda still lists the reconsideration as planned work.

Canada’s approach looks slow next to the U.K., but it has one advantage over the U.S.: the core rules are written into statute, which makes them harder to unwind with a change of government or a lawsuit.

What changes for consumers

When the system goes live, the day-to-day changes should be modest but meaningful:

  • No more password sharing. Connecting an app will look more like “Sign in with your bank,” where you approve specific data on your bank’s own screen.
  • Clearer control. You’ll be able to see which apps have access and revoke it. Consent expires after at most a year.
  • Better protection. The liability rules mean you’re not on the hook for losses within the framework unless you were grossly negligent.
  • Easier switching, eventually. Once write access arrives, moving accounts or paying directly from your bank should get simpler.

If you’re making a big financial decision based on a new app or service, it’s worth checking with a financial adviser, and confirming that the provider is accredited once the Bank of Canada’s registry is live.

What changes for fintech startups

For Canadian fintechs, the framework is both a gift and a compliance project. The upside is reliable, standardized access to data from every major bank, without fragile scraping scripts that break whenever a bank redesigns its login page.

The costs are real, though. Startups will need accreditation, insurance or comparable financial guarantees, security controls and record-keeping that meets the Bank of Canada’s standards. Some may rely on accredited intermediaries rather than connecting directly. And derived data stays out of scope, so fintechs will need to build their own analytics on top of raw transactions.

Founders should also plan for the gap. Screen scraping won’t be banned until the framework is fully operational, but building a business on it now means building on something with an expiry date. The practical move is to design for API access from the start and treat scraping as a temporary bridge. Given how much is still in draft, a conversation with a lawyer who knows financial regulation is worth having before you lock in an architecture.

The bottom line

After years of delay, Canada now has a law, a regulator and draft rules for open banking. What it doesn’t have is a technical standard or a launch date, and the realistic window for mandatory data sharing has slid into 2027 and beyond. The U.K. shows the payoff can be large, especially once payments are included. The U.S. shows how easily it can stall. Canada’s statute-first approach should make the eventual system durable. The challenge now is getting it built before another round of apps and consumers settles into the password-sharing habit for good.

Sources and further reading

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *