CSA data portability report flags KYC hurdles and open banking gaps

Canadian advisors are navigating fresh regulatory uncertainty as the CSA calls for alignment between securities data rules and the federal open banking framework

CSA data portability report flags KYC hurdles and open banking gaps

The Canadian Securities Administrators (CSA) has released a report identifying significant opportunities and persistent regulatory barriers in allowing investors to transfer their personal financial data between registered firms.

The report, produced by the CSA's FinHub Collaboratory and released on September 8, 2026, follows roughly 18 months of structured stakeholder consultation across Canada and the implications directly impact how wealth managers handle client onboarding and Know Your Client (KYC) obligations.

It examined how electronic KYC (e-KYC) data could be securely ported between registrants at the investor's request, reducing duplication when clients switch advisors or open accounts at multiple firms. The CSA's 2025–2028 Business Plan, which sets innovation and regulatory capacity as strategic priorities, underpins the project's mandate.

The Ontario Securities Commission did not participate in the project.

"As investor demand for data portability develops in Canada, this project has established a solid foundation of knowledge and stakeholder networks that will help regulators and firms navigate the new terrain," said Stan Magidson, CSA Chair and Chair and CEO of the Alberta Securities Commission. "We'll continue to proactively explore emerging technologies and business models, and the complex regulatory questions they pose, through structured stakeholder engagement."

KYC delegation rules are the central sticking point

Stakeholders consistently flagged uncertainty around whether using a third-party data portability service would violate KYC delegation restrictions under National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations (NI 31-103).

The companion policy to NI 31-103 states that KYC responsibilities cannot be delegated to a third party, and that collecting client information must amount to a meaningful interaction between the registrant and the client regardless of the tools or technology involved.

Some firms reported obtaining independent legal opinions on whether outsourcing parts of KYC data collection to a third-party service provider would satisfy those obligations.

The CSA acknowledged the issue and noted that regulatory clarification on how KYC obligations apply in a data portability context could help unlock the practical benefits of the initiative.

Privacy, consent, and what data should travel

Stakeholder feedback drew clear boundaries around what data ought to be portable.

There was broad agreement that only raw, factual, client-provided information such as name, address, investment objectives, or portfolio composition, should be transferable. Internal risk ratings, proprietary suitability assessments, and derived analytics should remain with the originating firm.

This distinction aligns with how open finance frameworks elsewhere in the world have approached scope, including the approach taken under Canada's emerging Consumer-Driven Banking (CDB) Framework.

On consent, stakeholders called for mechanisms that are explicit, revocable, and straightforward to manage, with the concept of a client-facing consent dashboard emerging as a practical model.

Quebec-based participants were particularly focused on alignment with Law 25, the province's updated private-sector privacy legislation, and raised concerns about duplication if provincial securities standards diverged from federal CDB Framework requirements.

Security was also a consistent theme. Participants recommended that the CSA consider establishing certifications or standards for data portability service providers, and stressed the importance of encryption, audit logging, and third-party vendor oversight.

The CSA itself acknowledged that greater volumes of data moving between firms broadens the attack surface for unauthorized access or interception.

No consensus on a preferred model and no live test, for now

The report found no clear winner among the four implementation models stakeholders considered: a central mandated utility, market-driven peer-to-peer sharing, third-party aggregators, and centralized data repositories.

Each carries trade-offs around accountability, cybersecurity risk, concentration, and governance.

Following its consultations, the CSA decided not to proceed with a Phase 3 live testing environment at this time. The primary reason: most participants wanted to see the federal CDB Framework's foundational data-sharing standards established before proceeding.

Premature standardization in the securities sector, several stakeholders warned, could lead to fragmentation if the two frameworks diverge. The federal government published proposed CDB regulations for consultation on June 27, 2026, after the Collaboratory's engagement phases were complete, providing additional detail on accreditation, consent, and security requirements.

What this means for advisors and wealth firms

The report's conclusions are cautious, but the direction of travel is clear. Data portability is coming to Canada's financial sector, and wealth managers should be monitoring how the CDB Framework evolves as it will set foundational standards that are likely to shape securities-specific portability requirements.

Advisors who rely on manual or fragmented KYC processes should also take note: the CSA's report suggests that the friction of KYC data collection is a problem regulators are committed to solving with or without a live testing environment in place.

Smaller firms may benefit most from streamlined client onboarding when portability eventually arrives.

The general consensus among stakeholders was that investors are the primary beneficiaries of data portability, with reduced friction for those switching providers or opening accounts at multiple firms. Larger institutions, by contrast, may have less incentive to facilitate the free movement of client data.

The CSA indicated it will use the feedback gathered to inform rulemaking, supervisory activity, and policy development as the broader ecosystem evolves. CSA staff expect to continue monitoring data portability developments and to engage further with market participants as the legislative and regulatory landscape takes shape.

LATEST NEWS