Bank sync privacy in Canada: a PIPEDA checklist

A PIPEDA checklist any Canadian can run on a bank-sync app: consent, processor, where data lives, how to withdraw it, and never share the password. Open banking is not live.

On this page
  1. A checklist you can run on any app
  2. Never share the PIN, password, or security answers
  3. What FCAC says about fintech apps
  4. PIPEDA: consent, purpose, safeguards, access
  5. Open banking is not live
  6. Finance Canada: about nine million Canadians
  7. A quiet product mention — not a trial heading

Bank sync privacy in Canada: a PIPEDA checklist

Someone pastes an online-banking password into a bank-sync screen because a US product named the aggregator. The useful 2026 job is not a vendor scorecard. It is a checklist you can run on any commercial app that wants Canadian financial data.

Official FCAC, Justice Canada, ESDC, and Finance Canada pages fetched for this note do not name a specific aggregator. The live Finnomia homepage (23 August 2026) does not name one either. Public privacy pages we fetched on that site also do not name a processor. This note will not invent a PIPEDA scorecard for a named vendor, and it will not say that Finnomia uses or does not use a named aggregator.

The answers that are on official pages: PIPEDA (Justice + ESDC), FCAC’s fintech / online-banking / open-banking rules, and Finance Canada’s screen-scraping sentence. Open banking is not live. Screen scraping is not open banking. Never share the bank password.

A checklist you can run on any app

Print this. Use it on the next connect screen, whoever built it.

Six-box PIPEDA checklist for any bank-sync app: why data is collected, who the processor is, where data lives, how to withdraw consent, never share the password, and open banking is not live

#CheckOfficial lineWhat you do
1Why is this collected?ESDC: you have the right to know why. PIPEDA (Justice): commercial collection, use, or sharing of personal information is with consent, for stated purposes.Read the purpose. If you cannot say it in one sentence, do not consent.
2Who is the processor?ESDC: know who is in charge of protecting the data. FCAC fintech page: read the app’s privacy and security policies.Find the legal name, the privacy contact, and any named processor. If the page will not say who holds the data, stop.
3Where does the data live?PIPEDA is the Canadian private-sector baseline for commercial activity. A privacy policy should say where information is stored and whether it leaves Canada.Look for a storage / transfer sentence. Absence is a reason to ask, not a reason to invent an answer.
4How do you withdraw consent?ESDC: expect use only for purposes you agreed to; access the information; request changes; complain. The Privacy Commissioner of Canada oversees compliance.Find the delete / disconnect / withdraw-consent path before you connect. If there is none, do not connect.
5Never share the passwordFCAC: never share PIN, password, or security answers with anyone, including third-party financial applications. You may void unauthorized-transaction protection.Do not type the bank password into an app. Ask the bank first. If in doubt, don’t.
6Open banking is not liveFCAC, 16 December 2025: open banking / consumer-driven banking is not available in Canada yet. Screen scraping is not open banking.Do not treat a password login as open banking. Do not treat a connect button as a live API.

Those six checks work on a Canada-native app, a US budget app, a spreadsheet add-on, or a “free” credit product. They are consumer rights and FCAC risk lines. They are not a vendor certification this note can invent.

Never share the PIN, password, or security answers

This is the bank-sync privacy line. It is not a how-to for sharing credentials.

The online banking page (17 October 2025): “don’t share your personal identification number (PIN), password or security questions and answers with anyone, not even family members.”

Same page: “If you give your online banking information to anyone, including a spouse, partner, family member or friend, you may: risk losing the protection against unauthorized transactions offered by your financial institution; be responsible for any unauthorized transactions on your account.”

Online banking: know your rights repeats it and notes this may happen if you provide personal or banking information to third-party financial applications.

A household that wants one view of the rent and the groceries still does not share the RBC password. That setup is a joint account, an authorized user, or a product that supports a shared view — household budgets in Canada. Bank sync is the same rule with a different screen.

What FCAC says about fintech apps

FCAC’s financial applications page (20 November 2025):

“Financial applications, also called fintech apps or fintechs, can help you manage your finances online. … They may also allow you to view all your financial products in one place.”

Using a fintech may require “username, personal identification number (PIN) or passwords you use to access your accounts online.”

“Providing your banking or credit card information to a fintech app may break your financial institution’s account or online banking agreement. This means your financial institution may hold you responsible in the event of unauthorized transactions.”

“If you're unsure if you should provide your personal banking information, ask your financial institution. If you still have doubts, don’t share your information.”

Read the app’s privacy and security policies. Those are the lines. This note does not invent a bank-by-bank approval list, and it does not invent a named-aggregator exception.

PIPEDA: consent, purpose, safeguards, access

A commercial bank-sync or budget app sits under Canadian private-sector privacy law.

Canada’s Privacy Act / PIPEDA page (19 June 2026): “For private sector organizations, the Personal Information Protection and Electronic Documents Act (PIPEDA) sets out the ground rules for how organizations involved in a commercial activity can collect, use or share personal information.”

The SIN Code of Practice (24 March 2026) restates those rules in consumer language. PIPEDA requires safeguards. You have the right to:

  • know why information is collected
  • expect appropriate collection
  • expect use only for purposes you agreed to
  • know who is in charge of protecting it
  • expect security safeguards
  • expect accuracy
  • access the information and request changes
  • complain

Financial information is generally sensitive. The Privacy Commissioner of Canada oversees compliance. Innovation, Science and Economic Development Canada has policy management for PIPEDA. GDPR and CCPA are not the Canadian private-sector baseline. Why a US budget toolkit is a different job — CAD, Interac, TFSA/RRSP, PIPEDA — is Canadian money apps vs US budget apps.

Open banking is not live

FCAC’s open banking page, dated 16 December 2025: “Open banking, also called consumer-driven banking, is not available in Canada yet.”

“Screen scraping is not open banking.” Apps that screen-scrape “require you to provide your online banking username and password” and “automatically log into your bank account as if they were you.” You may lose unauthorized-transaction protection even if the app has security measures.

When open banking is available, it uses an API: you authorize the bank to share data. You do not hand over the password. Canada is still on the first sentence: it is not available yet.

Finance Canada: about nine million Canadians

The screen-scraping scale figure is Finance Canada, not FCAC HTML. Budget 2025: Canada’s framework for consumer-driven banking (6 November 2025):

“about nine million Canadians currently share their financial data by providing their confidential banking credentials in a process known as screen-scraping.”

“The prohibition of screen scraping will come into force once the framework is fully operational.”

That is about nine million Canadians on a Finance Canada page. It is not a Mint user count and it is not a Finnomia user count. The framework is not fully operational. The prohibition is not in force today.

A quiet product mention — not a trial heading

Finnomia (homepage, 23 August 2026) markets Connect as Read-only access, always. The same page lists CAD native, PIPEDA compliant, and 256-bit encryption, and names RBC, TD, Scotiabank, BMO, CIBC, Tangerine, Wealthsimple and 50+ more. Finnomia is in open beta.

That is the product sentence this note will write. It does not invent a screen-scraping or API architecture behind “read-only.” It does not name an aggregator as Finnomia’s vendor — the live homepage and the public privacy URLs we fetched do not name one. Whether any named aggregator is or is not PIPEDA-compliant is UNKNOWN on official Canadian pages fetched here.

How that sits next to a Mint-era search — not as an “official Mint replacement” — is Mint alternative Canada.

If you still want to look at a Canada-native budget that markets a read-only connect, you can create an account. That is a quiet link, not a trial heading.

This is general information for 2026, not legal advice, not privacy-law advice, and not an FCAC, Justice, ESDC, or Finance Canada publication. Confirm account-agreement and privacy rules with your institution and on Canada.ca. Never share the bank password. Open banking is not live.

More from Finnomia