Letter to the Standing Senate Committee on Banking, Commerce and the Economy (BANC) (September 2026)

September 21, 2026

The Honourable Clément Gignac
Chair of the Standing Senate Committee on Banking, Commerce and the Economy
The Senate of Canada
Ottawa, Ontario
K1A 0A4
 

Dear Mr. Chair:

Further to the invitation from the Standing Senate Committee on Banking, Commerce and the Economy as part of its study on the elements contained in Division 6 of Part 4 of Bill C-31, I am grateful for this opportunity to provide the Committee with the following comments and recommendations.

The purpose of the Access to Information Act (ATIA) is to enhance the accountability and transparency of federal institutions in order to promote an open and democratic society and to enable public debate on the conduct of those institutions. This Act, which is founded on the principle that government information should be available to the public unless there is a compelling reason to restrict its disclosure, gives a right to access information under the control of government institutions, subject to limited and specific exemptions.

The Information Commissioner is a senior officer of Parliament appointed under the ATIA. A large part of my mandate involves investigating complaints submitted by individuals or organizations about access requests made under the ATIA to government institutions.

It is my firm view as Information Commissioner that public trust in government is strengthened when transparency is the default and confidentiality the exception. For that reason, I am of the opinion Parliament should exercise caution when expanding statutory prohibitions on disclosure. Each new confidentiality provision added to Schedule II reduces, to some degree, the information that may be subject to public scrutiny. While certain information unquestionably requires protection, such protections should be carefully tailored and limited to what is strictly necessary.

A transparent government is not merely an administrative objective; it is an essential condition for accountability, informed public debate and public confidence in democratic institutions. Preserving the broadest possible right of access, while protecting genuinely sensitive information, remains the most effective way to maintain that confidence.

Under the regular ATIA process, an institution must identify and justify the application of a specific exemption to deny access to information, such as those protecting confidential business information, security interests, or other privacy. In many cases, there must be an assessment of the nature of the information and the potential harm from disclosure.

Bill C-31 proposes to add subsections 62(1) and 63(1) of the Retail Payment Activities Act (RPAA) to Schedule II of the ATIA. Adding these provisions to Schedule II would in effect create a mandatory exemption from disclosure for all information described in those subsections, as section 24 of the ATIA prohibits the disclosure of any information the disclosure of which is restricted by any provision set out in Schedule II.

I am concerned by the legislative approach taken in Bill C-31, for two reasons:

  1. The information included in subsections 62(1) and 63(1) of the RPAA is very broad; and,
  2. The information included in subsections 62(1) and 63(1) that warrants protection would be sufficiently protected by the ATIA’s existing exemption provisions.

Breadth of subsections 62(1) and 63(1)

Once a provision is added to Schedule II, the institution may be able to rely on that statutory confidentiality provision rather than demonstrating that the requirements of another exemption have been met. As a result, a very broadly worded confidentiality provision can reduce scrutiny of individual records because the focus becomes whether the information falls within the statutory prohibition on disclosure, rather than whether protection of the information is necessary to protect a specific interest, such as privacy.

This can make administration easier for the institution because it does not need to undertake the same detailed exemption analysis that would otherwise be required under the Act. However, there is a transparency concern; some information relating to the Bank of Canada's supervision of payment service providers may not be commercially sensitive, security sensitive or otherwise, yet could nevertheless become inaccessible if captured by a broad confidentiality provision.

The objects of the RPAA include the supervision of payment service providers that perform retail payment activities, and the Bank of Canada’s monitoring and evaluation of trends and issues related to retail payment activities. However, subsection 62(1) of the RPAA provides that any information that the Bank obtains and any information prepared from that information is confidential. Subsection 62(2) only allows for disclosure of specific, limited information required to be made public under the RPAA: a public registry of payment service providers, a published list of refusals and revocations, and publication of violations, including names of providers and penalties. (Subsection 63(1) is the equivalent confidentiality provision for the Minister of Finance or their designated person or government authority.)

There is no question that some of the information collected under the RPAA should be protected. However, subsections 62(1) and 63(1) should not afford more protection than is necessary, and adding those provisions to Schedule II should strike the appropriate balance between transparency and confidentiality. When confidentiality provisions are necessary, they should be narrowly tailored so that only genuinely sensitive information is protected.

For example, section 37 of the Business Development Bank of Canada Act limits its confidentiality provision to information obtained in relation to its customers. Likewise, section 123 of the Global Minimum Tax Act limits confidential information to information that relates to one or more persons. It also specifies that it does not include information that does not directly or indirectly reveal the identity of the person to whom it relates. These are two examples of more limited provisions in Schedule II of the ATIA related to banking and financial information.

However, I note that recently, confidentiality sections 131 and 132 of the Consumer-Driven Banking Act, which are identical to the RPAA sections 62 and 63, were added to Schedule II of the ATIA in March of 2026. My office was not consulted on these provisions; however, had we been consulted I would have raised the same concerns. I am of the view that this formulation is overly broad, and I am concerned that it risks becoming the model for such provisions in future.

By referring to any information that the Bank obtains and any information prepared from that information, subsections 62(1) and 63(1) could be shielding from disclosure more information than necessary. These provisions could capture, for example, studies and trend analyses undertaken by the Bank that are created using information obtained from payment system providers, even if they are presented in aggregate or non-identifiable form and do not reveal information provided to the Bank. This does not appropriately balance transparency and access rights with confidentiality.

Existing protections in the ATIA

It is not readily apparent to me that there are categories of information protected by subsections 62(1) and 63(1) that are not already adequately protected under the existing exemptions in the ATIA.

The existing ATIA provisions include exemptions that specifically address privacy, third party confidentiality and national security concerns: section 19 is a mandatory exemption from disclosure for personal information, and section 20 is a mandatory exemption for confidential third-party information. Section 15, for its part, can be applied to refuse disclosure of information relating to the conduct of international affairs, the defence of Canada or the detection, prevention or suppression of subversive or hostile activities when disclosure of that information could reasonably be expected to be injurious to one of these interests.

Many other exemptions in the ATIA may, in certain circumstances, be applicable to specific information obtained under the RPAA. These include the section 13 exemption for information obtained in confidence from foreign governments and international organizations; and the section 16 exemption for information the disclosure of which could be harmful to the enforcement of a law or which could facilitate the commission of an offence.

By way of comparison, the Reserve Bank of Australia’s Payment Systems Board is subject to Australia’s Freedom of Information Act. The Australian Act does not provide a blanket confidentiality provision for the information obtained by the Board. In response to access requests, the Bank has released studies regarding retail payment card costs and surcharges. Exemptions were applied to private sector information under their confidential third-party information exemption, but the majority of the information contained in the studies was disclosed.

In my view, the proposed amendment does not appear to be addressing a genuine gap in the ATIA; it appears to be adding an additional layer of protection that may not be necessary.

Finally, I wish to convey to you a more general concern I have with the existence of Schedule II of the ATIA. In my view, and in the view of my predecessors, section 24 unnecessarily complicates the scheme of the ATIA and results in a lack of clarity and specificity which is contrary to the recognized principles of the ATIA. It is far more desirable for any exemptions to the right of access to be set out clearly in the ATIA itself rather than to be located in other legislation. The trend since the inception of the ATIA has been to substantially increase the number of provisions that are listed in Schedule II, with the number of listed provisions having increased from 33 in 1983 to 50 in 2000, 60 in 2012, to 73 today.

I trust that this information will be of assistance in your deliberations and I remain at the disposal of the committee.

Yours very truly,

Signature Caroline Maynard

Caroline Maynard
Information Commissioner of Canada

c.c.:

Mr. Toni Varone, Deputy Chair
Standing Senate Committee on Banking, Commerce and the Economy

Mr. Matthieu Boulianne, Clerk 
Standing Senate Committee on Banking, Commerce and the Economy

Date modified:
Submit a complaint