Screen Scraping Is Dying. What Replaces It Matters More Than You Think
Canada's Consumer-Driven Banking Act bans credential sharing, but the prohibition isn't in force. What that means for lenders relying on bank data today.
Alfred BEditorial Reviews
There is a sentence in Canadian law that makes screen scraping an offence. There is a second document, published by the same government three months later, explaining that the sentence will not take effect for some time yet. Both are true, and the gap between them is where every Canadian lender's bank-data strategy currently lives.
Section 171 of the Consumer-Driven Banking Act prohibits accessing a consumer's data using that consumer's authentication information. The prohibition is law. It has not been brought into force, and the Department of Finance Canada has said it will consult before setting a date. Credential sharing remains lawful today, with a legislated ending and no timetable.
That is an unusual position, and it is worth understanding precisely, because the planning question is not whether scraping ends. It is what replaces it, and what that swap changes about reliability, liability and the applicant's experience.
What does the Act actually prohibit?
Section 171 of the Consumer-Driven Banking Act reads:
Subject to the regulations, an individual or entity must not, for the purposes of providing a consumer in Canada with a product or service, use an interface or application to gain direct access to the consumer's data using the consumer's authentication information.
Section 2 of the same Act defines authentication information as any password or other information a consumer creates or adopts to authenticate their identity. Put together, that is a direct prohibition on the credential-handover model: the applicant gives you their online banking login, and software logs in on their behalf to retrieve data.
Two details in the drafting matter. The prohibition opens with "subject to the regulations," which means carve-outs are contemplated and have not been written. And contravening the Act is an offence, not merely a regulatory breach.
Why isn't it in force?
Because the government said so explicitly. From the Canada Gazette, Part I, published 27 June 2026 alongside the draft Consumer-Driven Banking Regulations:
The Act includes a prohibition on screen scraping that is not required to operationalize the broader framework and will not be brought into force until broader consultation and policy development have taken place.
The same document adds that the Department of Finance Canada will continue to consult with stakeholders to determine an appropriate timeline for bringing the prohibition into force, along with the parameters of the ban, which would be articulated in regulation at a future date.
The logic is sequencing rather than hesitation. Roughly nine million Canadians currently share their financial data by providing confidential banking credentials, according to the Department of Finance Canada's Budget 2025 materials. Switching off the mechanism those nine million people use, before the sanctioned alternative is accredited and operating at scale, would strand a large amount of ordinary financial activity. The replacement has to work first.
What is the actual problem with credential sharing?
The Government of Canada's own characterization, from the June 2026 Canada Gazette, is that credential sharing is an unregulated and technologically unsecure practice that can negatively impact consumers by posing increased security, liability and privacy risks, leaving them without recourse if something goes wrong, such as a data leak of their personal or financial information.
The recourse point is the sharpest one, and it is easy to miss. Sharing online banking credentials with a third party can affect the protection a consumer's bank offers against unauthorized transactions, a point the Financial Consumer Agency of Canada made in its May 2024 briefing to the House of Commons Standing Committee on Finance. In the same material, FCAC noted that only 18% of surveyed respondents understood that consumer protections differ between fintech applications and bank applications.
So the practice sits on an informed-consent problem. Most people handing over a password do not know what they are trading away.
Credential access against framework access, per the Consumer-Driven Banking Act and the June 2026 Canada Gazette:
| Credential sharing (today) | Framework access (phase one) | |
|---|---|---|
| How access is granted | Consumer hands over banking password | Consumer directs sharing between accredited participants |
| Legal status | Lawful; prohibition passed but not in force | The sanctioned route |
| Who is accountable | Undefined between bank, aggregator and lender | Defined participants under Bank of Canada supervision |
| Consumer recourse | Limited; bank protections may be affected | Framework participants, external complaints body |
| Durability | Breaks when a bank changes its login | Standardized access |
What changes when the swap happens
The technical change is smaller than the structural one.
Under credential sharing, the difficult part of the business is maintaining thousands of brittle connections to individual institutions, and that difficulty is itself the product. Under an accredited framework, connections standardize. The hard problem stops being access.
Which means the value migrates. It moves to consent management, to the quality of interpretation applied to the data once it arrives, and to the design of the intake experience wrapped around the connection step. The question a lender should be asking a vendor shifts accordingly. "How many institutions can you connect to?" is a question the framework is designed to neutralize. "What do you do with the data once it arrives, and what does your connection step do to my completion rate?" is not.
What to do while the clock is unset
The unsatisfying truth is that nobody can tell you when this lands. The Department of Finance Canada has committed to consulting first, and no indicative date exists in any primary source. Neither does the eventual shape of the carve-outs contemplated by "subject to the regulations."
That argues for work that pays off either way:
- Document your dependency. Which products rely on credential-based access today, through which vendors, under which consent language. This is usually broader than the documentation suggests.
- Improve the consent screen now. Plain-language, purpose-specific consent outperforms a credential wall under today's rules and transfers entirely to tomorrow's.
- Develop the interpretation layer. Income recognition and cash-flow signal extraction are underwriting assets you can build on scraped data and run on framework data later.
- Ask vendors which accreditation pathway they intend to use. The draft regulations set out four, by entity type.
- Participate in the consultation if the parameters affect you. Comments on the draft regulations were open through August 2026, and further consultation on the prohibition itself is promised.
None of this requires knowing the date. All of it is cheaper to do before the date is announced than after.
Common questions
Is screen scraping illegal in Canada right now?
No. Section 171 of the Consumer-Driven Banking Act prohibits credential-based access, but the Canada Gazette states the prohibition will not be brought into force until broader consultation and policy development have taken place.
When will the screen scraping ban take effect?
No date has been published. The Department of Finance Canada has said it will consult with stakeholders to determine an appropriate timeline and the parameters of the ban.
How many Canadians use screen scraping?
About nine million Canadians currently share financial data by providing their confidential banking credentials, according to the Department of Finance Canada's Budget 2025 materials.
What counts as authentication information?
The Act defines it as any password or other information a consumer creates or adopts to authenticate their identity.
Does sharing my banking password affect my protections?
It can. FCAC has noted that consumers who share credentials may lose the protection their bank offers against unauthorized transactions.
Carousel's intake flows use consent-first bank connections with document fallback where connections aren't possible. See how verification fits your flow


