Privacy commissioner flags areas of improvement in pitched consumer-driven banking regulations

Recommendations included changes to accreditation criteria and provisions to clarify the definition of publicly available data
Privacy commissioner flags areas of improvement in pitched consumer-driven banking regulations

The Office of the Privacy Commissioner of Canada has flagged privacy-protective measures that could be improved in its response to the federal government’s pitched consumer-driven banking regulations.

In a submission to Finance Canada, the OPC suggested that s.2 of the regulations include certain data elements to which the Consumer-Driven Banking Act would apply. The commissioner also recommended that the accreditation criteria be modified.

The OPC suggested that s.42 of the regulations be reworded to clarify that the definition of publicly available data does not cover data in which consumers have a reasonable expectation of privacy. Moreover, it recommended that the regulations include an overarching requirement for participating entities to safeguard data with appropriate security measures based on data sensitivity.

Finally, the commissioner suggested adding a provision to clarify that the agreements and arrangements that the bank may enter into under s.5 of the CDBA may facilitate the coordination of the respective activities of the bank and of other government authorities and regulatory bodies as well as for the disclosure of information necessary for the purpose of such coordination.

Lack of detail regarding data elements

The OPC found that the data elements subject to the CDBA were not adequately detailed to enable a consumer to know the exact data that would be collected. These elements include information involving consumer identity; account numbers, branch numbers and other identifiers; terms of product or service provision; current or past balances owed; information related to completed, pending, or pre-authorized transactions; and information respecting products and services provided or available to consumers.

Enhancement of accreditation process’ effectiveness

The regulations outlined criteria for four accreditation pathways supervised by the Bank of Canada: non-streamlined accreditation, streamlined accreditation for entities registered under the Retail Payments Activities Act, accredited third-party service providers (ATPSPs), and federal and provincial financial institutions. The OPC suggested that the accreditation criteria be changed as follows:

  • ATPSP applicants must have implemented adequate security protections for the sensitivity of data under subsection 14(1) of the regulations, supported by evidence of implementation
  • Streamlined and federal and provincial financial institution applicants must disclose to the bank information regarding the complaint procedures under s.105 of the CDBA
  • ATPSP applicants that share or collect data for a participating entity must present evidence of compliance with the technical standard
  • Federal and provincial financial institution applicants must show that the character and integrity of persons with significant responsibility for consumer-driven banking have been evaluated
  • Federal and provincial financial institution applicants must show that they have secured insurance or other guarantees to mitigate data management risks under the consumer-driven banking framework
  • ATPSPs overseeing authentication for participating entities must disclose information on customer authentication
  • Streamlined and federal and provincial financial institution applicants must share consumer dashboard information as required for non-streamlined applicants under paragraph 6(1)(n) of the regulations

Potential harmful effect of consent for publicly available data exception

Paragraph 42(c) of the regulation stipulates that participating entities can use publicly available data without consent for purposes beyond that offered to consumers. The OPC said this could open Canadians’ personal data up to inappropriate use.

Security protections unresponsive to technological change

S.37 of the regulations listed security safeguards that entities must implement, including the identification and addressing of system vulnerabilities, device and system security measures, and the implementation and testing of incident-response plans. However, the OPC noted that a prescribed list may hinder entities from responding to changing security risks adequately.

Nonetheless, the OPC threw its support behind the consumer-driven banking regime’s goals. It also backed elements in the regulations that would ensure privacy protection for consumers, including permitting consumers to safely and securely decide the destination of their data; requiring participants like banks to report data breaches to the Bank of Canada; and using multi-factor authentication in response to data disclosure requests.

Improvement to consumer-driven banking framework oversight

The OPC recommended the inclusion of provisions explicitly facilitating coordination and information sharing between the Bank of Canada and the commissioner to ensure efficient and effective supervision of the consumer-driven banking framework. The OPC suggested provisions similar to subsections 37(5) and 64(3) of the Privacy Act and section 15.1 of the National Security and Intelligence Review Agency Act; these provisions allow the commissioner to coordinate with the National Security and Intelligence Review Agency, preventing unnecessary work duplication.

Nonetheless, the OPC indicated that it backed the consumer-driven banking regime’s aims and elements such as those permitting consumers to safely and securely direct their data’s destination, requiring participants like banks to report data breaches to the Bank of Canada, and using multi-factor authentication in responding to data disclosure requests.

Firm(s)

Privacy Commission of Canada