Canada is about to dismantle the digital walls around its financial data. After years of trailing other G7 countries, the federal government has confirmed that 2026 marks the official launch of consumer-driven banking, the framework most people call open banking.
The Consumer-Driven Banking Act received Royal Assent in March 2026. The Bank of Canada now oversees the system. And for the first time, Canadians will have a legal right to direct their financial information away from the Big Six banks and toward the apps of their choice.
But here’s what most coverage misses: the framework doesn’t just create new pipes for your data. It replaces a practice that nine million Canadians already do, a practice the Department of Finance calls “an unregulated and technologically unsecure practice.”
The nine million password problem
Right now, if you want a budgeting app to see your transactions, you hand it your bank username and password. The app logs in as you, scrapes your data from the bank’s website, and shows it back to you in a nicer interface. This is called screen scraping.
The Department of Finance’s own analysis calls screen scraping “an unregulated and technologically unsecure practice” that poses security, liability, and privacy risks. When you share your banking credentials, you often void your bank’s fraud protection. If the app gets breached, your bank login is exposed. If something goes wrong, you’re left negotiating with a bank, an app provider, and a data aggregator, and nobody is clearly responsible.
Roughly nine million Canadians currently share their credentials this way. That’s not a fringe behavior. That’s the normal way people use financial apps in Canada.
The new framework replaces screen scraping with application programming interfaces, APIs. Instead of handing over your password, you direct your bank to share specific data with accredited third parties over secure rails. Your bank authenticates you. The app gets access to your transactions, not your login. You don’t void your fraud protection.
How the framework actually works
The proposed regulations, published in the Canada Gazette on June 27, 2026, set the operating rules. Here’s what they require.
Accreditation. Not every app can plug into the framework. Providers must be accredited by the Bank of Canada. They need to meet defined security standards, maintain 99.5% monthly API uptime, and carry appropriate insurance. Penalties for violations reach $1 million for individuals and $10 million for participating entities.
Consent. You control what data gets shared, with whom, and for how long. Consent must be renewed at least every 12 months. Data recipients are responsible for obtaining and managing your consent. Data providers, your bank, are responsible for authenticating you.
History. Participating banks must make a minimum of 24 months of transaction history available through the API. That’s two years of data, accessible to any accredited app you choose.
Phased rollout. Phase 1, read access, launches in 2026. Deposit and payment accounts come first, followed by lending accounts, then registered and non-registered investment accounts. Phase 2, write access, is targeted for mid-2027. Write access means payment initiation and smooth account switching, contingent on Canada’s Real-Time Rail being live.
What this means for your budget
Here’s where it gets interesting for anyone who tracks their spending.
Under the framework, a budgeting app could pull your transaction history directly from your bank, with your consent, without ever seeing your password. No screen scraping. No credential sharing. No voided fraud protection.
That sounds like a win. And for many people, it is.
But the framework also creates a system where your financial data flows through more pipes than ever before. Every accredited app that gets access to your data is a potential breach point. The regulations set security standards, but standards don’t prevent every breach. They just define the minimum.
The current screen scraping mess is genuinely risky. But at least it’s decentralized. Every app has its own fragile, janky connection to your bank. The new framework centralizes data sharing through regulated APIs. That’s more secure in theory. It also means the data is more portable, more accessible, and more available to third parties than it has ever been.
The Basalt angle
Basalt doesn’t need open banking.
That might sound strange coming from someone building a budgeting app in Canada. But the whole point of file-based budgeting is that your financial data lives in files you own, not on a server somewhere. You import your transactions manually, from screenshots, PDFs, or bank files you download yourself. The app never logs into your bank. It never sees your credentials. It never needs an API to your account.
When open banking launches, millions of Canadians will suddenly have a easier way to share their data with apps. The apps that benefit most are the ones that currently rely on screen scraping, the ones that need your bank login to function. Those apps will become more secure and more reliable.
But the framework doesn’t change the fundamental question: do you want your financial data flowing through third party servers, even regulated ones, or do you want it staying on your device?
Basalt takes the latter approach. Your vault is a file on your Mac or iPhone. When you sync, it goes through your iCloud account, your infrastructure, your control. No accredited third party. No API pipes. No consent renewal every 12 months.
The framework makes data sharing safer. It doesn’t make it unnecessary to think about who holds your data in the first place. This is the same pattern we’ve seen before: a system built on collecting your data, dressed up as convenience. The psychology of why that’s dangerous is something we’ve written about.
The bigger picture: open finance
Consumer-driven banking is the first step. The next one is open finance.
The 2025 Budget introduced a data mobility right that will let consumers move their financial data across sectors, from banking to insurance, wealth management, and telecom. The framework currently covers banking. The plan is to expand it.
Open finance would let you move your verified financial history when switching mortgage providers, insurance companies, or investment advisors. It would let a small business authorize read-only access to real-time accounting data so a lender can see how the firm is actually performing.
The government’s own analysis projects roughly $13.2 billion in economic benefits over ten years against $457.7 million in costs. Those numbers assume the framework actually delivers on competition and innovation.
Whether it does depends on implementation. If accreditation becomes a barrier that only the biggest fintechs can clear, the Big Six stay in control. If technical standards become a moat, nothing changes. If liability rules are unclear when breaches happen, consumers are still left negotiating with institutions they never met.
The framework is real. The timeline is set. The question is whether it delivers competition or just digitizes the current concentration.
FAQ
Q: Is open banking available in Canada right now? A: Not yet. The Consumer-Driven Banking Act received Royal Assent in March 2026, and the proposed regulations were published June 27, 2026. Phase 1, read access, is expected to launch in 2026. Phase 2, write access, is targeted for mid-2027.
Q: Do I have to use open banking? A: No. Participation is voluntary for consumers. You can keep using your bank’s online banking, keep screen scraping if apps still offer it, or keep importing transactions manually. The framework creates an option, not an obligation.
Q: Is open banking safer than screen scraping? A: The government says yes, and the reasoning is sound. APIs don’t require you to share your bank password. You don’t void your fraud protection. Accredited providers must meet security standards. But “safer” isn’t “risk-free.” Every new data pipe is a potential breach point.
Q: Will Basalt use the open banking API? A: No. Basalt is file-based. You import transactions manually or from screenshots and PDFs. The app never connects to your bank, so it doesn’t need the API. Whether open banking exists or not doesn’t change how Basalt works.
Q: What happens to my data if an accredited app gets breached? A: The framework includes liability rules, but the specifics depend on the situation. Screen scraping is risky partly because nobody is clearly responsible when things go wrong. The new framework assigns responsibility: data providers authenticate, data recipients manage consent. But “clearer than screen scraping” doesn’t mean “perfect.”
The short version
Nine million Canadians currently share their bank passwords with apps through screen scraping. The consumer-driven banking framework replaces that with secure APIs, accreditation, and consent rules. Phase 1 launches in 2026. Phase 2 follows in 2027.
The framework makes data sharing safer. It also makes data more portable and more available to third parties than ever before. Whether that’s a net positive depends on implementation, enforcement, and whether you’re comfortable with your financial data flowing through more pipes.
Basalt takes a different approach. Your data stays on your device, in files you own, synced through your infrastructure. No APIs. No accreditation. No third party holding your financial life.
Privacy isn’t a feature you add on later. It’s a design choice.
Learn more about how file-based budgeting works and why it matters for your privacy.
Or if you want to see what a privacy-first budgeting app looks like, check out Basalt.
Want more insights on how financial data actually moves in Canada?
Subscribe to the Basalt newsletter. No spam, no data selling, just practical takes on privacy and your finances.