Canadian financial institutions now have a clearer pathway to obtaining approval for sharing client personal information without explicit consent to combat money laundering and terrorist financing. The Office of the Privacy Commissioner of Canada (OPC) released comprehensive guidance on July 9, 2026, designed to assist these firms in developing and submitting codes of practice that align with the Commissioner’s rigorous privacy standards. This initiative represents a significant step in balancing the critical need for financial crime detection with the fundamental right to privacy for Canadians.
The new guidance stems from legislative amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), which came into effect in March 2025. These amendments empower designated reporting entities to share an individual’s personal information amongst themselves under specific circumstances, even without the individual’s knowledge or consent. However, a crucial prerequisite for this data sharing is the establishment and subsequent approval of a robust code of practice by the Privacy Commissioner.
Navigating the New Landscape: Guidance for Financial Firms
The OPC’s guidance is specifically tailored for "reporting entities," a broad category encompassing institutions such as chartered banks, credit unions, trust companies, and providers of life insurance and loan services. Participation in developing and submitting a code of practice is voluntary; however, any firm intending to leverage the new legislative provisions for information sharing will find this guidance indispensable. The Commissioner’s office emphasizes that the development of a code is not mandatory unless a firm actively plans to engage in this type of inter-entity data sharing for anti-money laundering (AML) and counter-terrorist financing (CTF) purposes.
Essential Components of an Approved Code of Practice
The published guidance meticulously outlines the essential elements that a code of practice must contain to secure the Privacy Commissioner’s approval. At its core, a compliant code must clearly:
- Identify Bound Entities: Explicitly name all the financial firms that will be subject to the code and participate in the information-sharing framework. This ensures transparency and accountability within the participating group.
- Define Permissible Information: Specify precisely what categories of personal information can be shared. This involves a detailed description to prevent over-collection or inappropriate disclosure.
- Articulate Purpose and Method: Clearly describe the specific purposes for which the information will be shared, focusing on the detection and prevention of money laundering, terrorist financing, and sanctions evasion. Furthermore, the code must detail the precise methods and channels through which this information will be exchanged.
- Outline Protection and Retention: Establish stringent protocols for how the shared information will be protected against unauthorized access, use, or disclosure, and define the duration for which it will be retained. These measures are paramount to mitigating privacy risks.
- Demonstrate Equivalent or Superior Protection: Crucially, the code must demonstrate that it provides a level of personal information protection that is equivalent to, or greater than, that mandated by Canada’s federal private-sector privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA).
Aligning with Foundational Privacy Principles
To assist firms in meeting the stringent PIPEDA equivalency requirement, the guidance elaborates on ten core privacy principles that are fundamental to Canada’s privacy landscape. These principles, which include accountability, limiting collection, safeguards, accuracy, openness, individual access, and complaint handling, are explained in the context of the specific information-sharing scenarios envisioned by the PCMLTFA amendments. The OPC details its expectations under each principle, providing practical insights into how firms can integrate these tenets into their proposed codes of practice. This approach underscores the Commissioner’s commitment to ensuring that privacy safeguards remain robust even when information is shared without direct consent.
A Structured Approach to Application and Review
The OPC has also provided clear instructions regarding the application process and timeline. Applicants are strongly advised to engage with the Commissioner’s office early in the development of their codes. Furthermore, on the same day that a code is formally submitted for review, reporting entities must also notify the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). FINTRAC’s involvement is considered vital, as the agency is well-positioned to inform the assessment process due to its mandate in monitoring and analyzing financial transactions for suspicious activities.
Once a code is submitted, the Privacy Commissioner has a statutory period of 120 days to render a decision. This timeframe can be extended by an additional 15 days, and the clock can be paused if the Commissioner requires further information from the applicant. This structured review process aims to ensure thoroughness while providing a predictable timeline for financial institutions.
Ongoing Obligations and Regulatory Oversight
The responsibilities of financial firms do not conclude upon receiving approval for their codes of practice. Any subsequent revisions or amendments to an approved code necessitate notification to the Privacy Commissioner. The Commissioner then has 30 days to determine if the proposed changes are significant enough to warrant a full reassessment and a new application. This oversight mechanism ensures that privacy protections remain current and effective.
Moreover, approved codes of practice have a defined validity period. They must be resubmitted for renewal and re-approval every five years. Failure to do so will result in the code lapsing, thereby revoking the authority to share information under its provisions. This quinquennial review cycle reinforces the dynamic nature of privacy regulations and the need for continuous adaptation.
Reinforcing the Fight Against Financial Crime
Privacy Commissioner Philippe Dufresne emphasized the dual objective of the new guidance. "This new guidance will support organizations as they establish codes of practice that maintain strong privacy protections in the context of information sharing meant to detect and prevent money laundering, terrorist financing, and sanctions evasion," he stated. His remarks highlight the government’s commitment to equipping financial institutions with the tools they need to combat increasingly sophisticated financial crimes while upholding the privacy rights of Canadians.
The Commissioner’s office also issued a crucial disclaimer, clarifying that the guidance is intended to assist applicants and does not constitute legal advice. Financial institutions are encouraged to seek their own legal counsel to ensure full compliance with all applicable laws and regulations.
Context and Background: The Evolving Threat Landscape
The amendments to the PCMLTFA and the subsequent guidance from the OPC are a direct response to the persistent and evolving threat of financial crime. Money laundering, which involves disguising the origins of illegally obtained money, and terrorist financing, the provision of funds for terrorist activities, pose significant risks to Canada’s economic stability and national security. Sanctions evasion, another area of concern, undermines international efforts to address geopolitical conflicts and human rights abuses.
Historically, information sharing among financial institutions for AML/CTF purposes has been constrained by strict privacy laws. While collaborative efforts were possible, they often required explicit consent or were limited to specific, narrowly defined circumstances. The March 2025 amendments recognized that a more proactive and collaborative approach was necessary to effectively counter these sophisticated criminal networks.
Supporting Data and International Trends
The need for enhanced information sharing is underscored by global trends in financial crime. According to reports from various international bodies, including the Financial Action Task Force (FATF), money laundering and terrorist financing activities continue to pose a substantial global threat. The FATF, an intergovernmental organization that sets international standards to combat money laundering and terrorist financing, has consistently highlighted the importance of effective public-private partnerships in this fight.
In recent years, numerous jurisdictions have explored and implemented measures to facilitate greater information exchange within the financial sector for AML/CTF purposes, often with a focus on balancing privacy considerations with security imperatives. Canada’s approach, through the PCMLTFA amendments and the OPC’s guidance, aligns with this broader international movement towards strengthening the financial sector’s defenses against illicit finance.
While specific data on the volume of suspicious transactions detected through such inter-entity sharing in Canada prior to these amendments is not readily available, anecdotal evidence from industry stakeholders has often pointed to information silos as a potential impediment to identifying complex laundering schemes that span multiple institutions. The new framework aims to break down these silos in a controlled and regulated manner.
Broader Impact and Implications
The introduction of this guidance has several significant implications for Canada’s financial sector and its clients:
- Enhanced AML/CTF Capabilities: Financial institutions are now better equipped to identify and report suspicious activities, potentially leading to a more effective disruption of money laundering and terrorist financing networks. This could translate into fewer illicit funds circulating within the Canadian economy and a reduced risk of Canada being used as a conduit for criminal finances.
- Increased Compliance Burden and Opportunity: While the guidance aims to clarify the process, developing and maintaining a compliant code of practice will require significant investment in legal, compliance, and IT resources for participating firms. However, it also presents an opportunity for these institutions to proactively demonstrate their commitment to both financial integrity and robust privacy protection.
- Heightened Privacy Scrutiny: The OPC’s detailed expectations under each privacy principle signal a heightened level of scrutiny on how personal information is handled. This reinforces the importance of privacy-by-design principles within financial institutions.
- Client Confidence: By establishing clear rules and oversight for information sharing, the framework aims to foster greater confidence among clients that their personal data is being handled responsibly, even when used for purposes beyond direct service delivery. Transparency about the existence and purpose of these codes will be key to maintaining this trust.
- Potential for Industry-Wide Standards: As more firms develop and submit codes, a de facto industry standard for information sharing in AML/CTF efforts may emerge, further harmonizing practices across the sector.
Conclusion
The Office of the Privacy Commissioner of Canada’s guidance on codes of practice for information sharing under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act marks a pivotal moment for Canada’s financial sector. It provides a much-needed roadmap for institutions seeking to collaborate in the critical fight against financial crime, while simultaneously reinforcing the imperative of safeguarding client privacy. The detailed requirements and the structured review process underscore the government’s commitment to striking a careful balance, ensuring that the integrity of Canada’s financial system is protected without compromising the fundamental privacy rights of its citizens. The success of this initiative will hinge on the diligent application of these guidelines by financial firms and the continued oversight by the OPC and FINTRAC.
The full text of the Guidance on Submitting Codes of Practice under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations is available at: https://www.priv.gc.ca/en/privacy-topics/surveillance/police-and-public-safety/financial-transaction-reporting/gd_cp_pcmltfr/
