On July 9, 2026, the Privacy Commissioner of Canada (the Commissioner) released guidance (the Guidance) to assist financial reporting entities in preparing and submitting a code of practice (Code of Practice) governing the sharing of personal information required under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (Regulations).

The Guidance is intended for reporting entities subject to the PCMLTFA, such as banks, credit unions, trust companies and providers of life insurance and loans.  In March 2025, legislative amendments came into force that permit reporting entities to share personal information with one another, without an individual’s knowledge or consent, in limited circumstances in accordance with the Regulations. Before engaging in such information sharing, reporting entities must establish a Code of Practice governing the information sharing and have the Code of Practice be approved by the Commissioner. The purpose of the Code of Practice is to enable better detection and prevention of money laundering, terrorist financing, and sanctions evasion while maintaining appropriate privacy protections.

The Guidance clarifies the types of information reporting entities should include in their Codes of Practice to demonstrate they meet the requirements for approval as set out at section 160 of the Regulations.  Among those requirements, applicants must show that the Code of Practice provides a level of protection for personal information that is substantially the same as, or greater than, the protection provided for under the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law.

To assist reporting entities in preparing compliant Codes of Practice, the Guidance discusses the Commissioner’s expectations with respect to each of PIPEDA’s core privacy principles: Accountability; Identifying Purposes; Limiting Collection; Limiting Use, Disclosure and Retention; Accuracy; Safeguards; Openness; Individual Access; and Challenging Compliance. The Guidance also provides practical direction on the process for amending an approved Code of Practice and confirms that approved Codes of Practice must be submitted for reapproval every five years.

For more information, see the full Guidance available here.

Summary By: Victoria Di Felice

 

E-TIPS® ISSUE

26 07 29

Disclaimer: This Newsletter is intended to provide readers with general information on legal developments in the areas of e-commerce, information technology and intellectual property. It is not intended to be a complete statement of the law, nor is it intended to provide legal advice. No person should act or rely upon the information contained in this newsletter without seeking legal advice.

E-TIPS is a registered trade-mark of Deeth Williams Wall LLP.