CSA data portability report flags KYC hurdles and open banking gaps
Quebec-based participants were particularly focused on alignment with Law 25, the province’s updated private-sector privacy legislation, and raised concerns about duplication if provincial securities standards diverged from federal CDB Framework requirements.
Security was also a consistent theme. Participants recommended that the CSA consider establishing certifications or standards for data portability service providers, and stressed the importance of encryption, audit logging, and third-party vendor oversight.
The CSA itself acknowledged that greater volumes of data moving between firms broadens the attack surface for unauthorized access or interception.
No consensus on a preferred model and no live test, for now
The report found no clear winner among the four implementation models stakeholders considered: a central mandated utility, market-driven peer-to-peer sharing, third-party aggregators, and centralized data repositories.
Each carries trade-offs around accountability, cybersecurity risk, concentration, and governance.