New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Fintech & financial services
Privacy & Security for Credit Unions & Caisses Populaires
Credit unions hold what fraudsters want most: SINs collected for tax slips, mortgage files, credit bureau reports and full transaction histories, all supervised by provincial prudential regulators that now examine IT risk directly. We help credit unions and caisses populaires build privacy and security programs that stand up to FSRA, BCFSA and CUDGC scrutiny, protect member data running on shared cores such as Fiserv DNA, and answer the questions boards have been asking since the Desjardins insider breach.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with Canadian credit unions from single-branch institutions with fewer than fifty staff to multi-billion-asset organizations, and with caisses populaires in the Desjardins network. Our usual contacts are the CEO or general manager, the VP Risk or CRO, a director of IT who is often one person supported by an MSP, the chief internal auditor, and a privacy officer who doubles as the compliance lead.
Engagements usually begin at a pressure point: FSRA's Information Technology Risk Management Guidance taking effect on April 1, 2024, an upcoming Risk-Based Supervisory Framework review, a core-banking or digital-banking conversion through Celero or CGI, a federal continuance project that would bring OSFI's B-13 and B-10 into play, or a bonding and cyber-insurance renewal with harder questions than last year.
Timing tends to follow the sector's own calendar. Fiscal year-end audits surface findings the board wants closed, AGM season in the spring puts governance in front of members, and regulator filing cycles set deadlines that a part-time privacy or security function struggles to meet alone.

Services
Privacy & security services for credit unions & caisses populaires
Each service below is scoped for how credit unions & caisses populaires actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Credit Unions & Caisses Populaires
vCISO for credit unions: security leadership that satisfies FSRA, BCFSA and CUDGC examiners, briefs the board, and steers core conversions safely.
Virtual Privacy Officer
Virtual Privacy Officer for Credit Unions & Caisses Populaires
Virtual Privacy Officer for credit unions: a named privacy lead answering OPC, OIPC and AMF questions about member data and retention schedules.
Penetration Testing
Penetration Testing for Credit Unions & Caisses Populaires
Penetration testing for credit unions: scoped web, mobile and branch-network testing that respects shared Celero and Central 1 production boundaries.
Incident Response Planning
Incident Response Planning for Credit Unions & Caisses Populaires
Incident response planning for credit unions: one plan meeting FSRA's ~72-hour notice, the AMF's 24-hour rule and PIPEDA reporting at once.
Privacy & Security Policy Development
Privacy & Security Policy Development for Credit Unions & Caisses Populaires
Policy development for credit unions: board-approved IT risk, outsourcing, insider-threat and retention policies mapped to FSRA guidance.
Privacy & Security Training
Privacy & Security Training for Credit Unions & Caisses Populaires
Security training for credit unions: role-specific sessions for tellers, marketing staff and the board, built around Desjardins-era insider risk.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Credit Unions & Caisses Populaires
Vendor security review for credit unions: assessing Celero, Central 1 and statement vendors where concentration risk is structural, not optional.
ISO 27001 Readiness
ISO 27001 Readiness for Credit Unions & Caisses Populaires
ISO 27001 readiness for credit unions: using the standard to operationalize FSRA's IT risk guidance, with expert-led prep and platform automation.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Credit Unions & Caisses Populaires
AI-PIA for credit unions: assessing member-service chatbots, AI fraud monitoring and Law 25 duties when a partner or vendor runs the model.
What you hold
Member data and the systems it moves through
A credit union's records go far beyond account balances, and they sit on a small set of member-owned shared platforms that concentrate the stakes.
Member master files
Identity documents, dates of birth and SINs gathered for tax reporting sit in the core banking system and are exactly the fields an insider or intruder monetizes first.
Lending and mortgage records
Loan origination files, mortgage documentation and pulled credit bureau reports combine income, debt and identity in one place, and often persist long after the loan closes.
Digital banking and payment channels
Online and mobile banking delivered through CGI Digital Banking, Interac e-Transfer, ATM and POS networks, and payments flowing through Central 1, including Real-Time Rail preparation.
Marketing data warehouses
Analytics extracts of member data built for campaigns are the precise pattern that failed at Desjardins, where warehouse copies on a shared drive were exfiltrated over 26 months.
Compliance and governance records
AML and FINTRAC documentation, board minutes, member-vote records and branch video or ATM footage each carry their own retention, access and disclosure obligations.
Regulatory map
Who regulates a credit union, and for what
The sector's defining trait is that prudential supervision is provincial, privacy law is layered, and both now reach directly into technology risk.
FSRA IT risk expectations in Ontario
Under the Credit Unions and Caisses Populaires Act, 2020, FSRA's guidance asks for notification of material IT risk incidents normally within 72 hours or sooner, filed through its online incident-reporting portal.
BCFSA supervision and CUDIC
In British Columbia the regulator that examines your practices also administers deposit insurance, so weak IT risk management is a prudential finding, not just a security gap.
Alberta's CUDGC oversight
The Credit Union Deposit Guarantee Corporation guarantees 100 per cent of deposits and provides risk-based regulatory oversight of Alberta Central and the province's twelve credit unions.
PIPEDA and the provincial PIPAs
Because credit unions engage in commercial activity, PIPEDA governs member data, with Alberta and BC PIPAs applying in-province and Alberta PIPA s. 34.1 making OIPC breach reporting mandatory.
Law 25 and the AMF for caisses
Québec caisses carry Law 25 duties, including a designated privacy officer, PIAs and incident registers, plus AMF incident reporting via E-Services within 24 hours with updates every three days.
OSFI after federal continuance
A credit union that continues federally becomes an FRFI subject to Guideline B-13, B-10 third-party risk expectations and 24-hour incident reporting, the path BC's Prospera and Sunshine Coast took.
What goes wrong
How credit unions actually get hurt
The sector's loss patterns are documented in regulator investigations and breach reports rather than vendor marketing, and they repeat.
Insider exfiltration
The OPC and CAI jointly investigated Desjardins after a malicious employee copied marketing-warehouse extracts to USB, affecting 9.7 million individuals and exposing safeguards, accountability and retention failures.
Social engineering of branch staff
Alberta's OIPC breach reporting and its decade-long PIPA Breach Report document recurring social-engineering and unauthorized-access incidents that map directly onto teller and MSR workflows.
Outages on shared banking platforms
Ransomware or a failure at a shared core or payments provider is a material IT risk incident, and provincial regulators expect prompt notification while members lose access to their money.
e-Transfer interception and account takeover
Credential phishing of members feeds Interac e-Transfer fraud, a trend OSFI and FCAC have flagged across the financial sector, and it lands on the credit union's fraud desk first.
Statement and transfer-vendor compromise
MOVEit-style breaches of file-transfer tooling, including one deployment that exposed roughly 100,000 Nova Scotians, mirror the outsourced statement-printing and reporting chains credit unions rely on.
Retention as a breach multiplier
Desjardins had no finalized destruction schedule, so the incident swept up far more members than it needed to, and regulators now probe retention practices when they size a breach.
When organisations call us
The moments that start an engagement
Credit unions rarely call about privacy in the abstract; a regulator, a conversion or an auditor puts a date on the calendar.
An exam or supervisory review is scheduled
FSRA, BCFSA or CUDGC has booked a Risk-Based Supervisory Framework review and the IT risk file is thinner than the board would like.
A core or digital-banking conversion
Moving to or upgrading Celero's Fiserv DNA core or CGI's member channels raises third-party, testing and incident questions the project plan did not budget for.
Federal continuance is on the table
Following the OSFI path means preparing for B-13, B-10 and 24-hour incident reporting well before the continuance date, not after.
Bonding or cyber-insurance renewal
The bonding carrier or cyber insurer now wants evidence of MFA, testing, incident planning and vendor oversight before quoting, and the renewal date is fixed.
An audit or board finding lands
Internal audit flags access, retention or insider-risk gaps, and directors who followed the Desjardins investigation want a credible remediation owner.
Credit Unions & Caisses Populaires: privacy & security questions, answered
PIPEDA applies because credit unions are engaged in commercial activity, and it always governs interprovincial and international data flows. In Alberta and BC, the provincial PIPAs govern in-province activity, and Alberta PIPA s. 34.1 makes breach reporting to the OIPC mandatory. Québec caisses operate under Law 25, which adds privacy-officer designation, PIAs, incident registers and administrative monetary penalties reaching $10 million or 2 per cent of turnover.
It depends on where you are incorporated. Ontario credit unions answer to FSRA under the Credit Unions and Caisses Populaires Act, 2020; BC institutions to BCFSA, which also administers CUDIC deposit insurance; Alberta institutions to CUDGC, which doubles as the deposit guarantor. OSFI only enters the picture if you continue federally and become an FRFI, at which point B-13 and B-10 apply. Desjardins caisses are overseen by Québec's AMF.
Because the joint OPC and CAI investigation turned one institution's failure into the sector's checklist. The findings on safeguards, accountability and retention describe controls every credit union is now measured against: who can reach warehouse extracts, whether access is reviewed, and whether member data is destroyed on schedule. Boards, examiners, insurers and internal auditors all read the same report, so the questions arrive from every direction.
No. Credit unions are expressly excluded from RPAA registration as payment service providers, which is one of the clearest ways the sector differs from fintechs and payment processors. That exclusion does not lighten the load elsewhere: provincial prudential guidance, privacy statutes and payment-network obligations through your central still apply in full.
Yes, and regulators say so. Cores, payments and statement printing concentrate on a handful of providers such as Celero, Central 1 and other CUSOs, so a single vendor incident can hit many credit unions at once. FSRA's third-party lens, and OSFI's B-10 for federally continued institutions, expect each credit union to understand that concentration, document it, and hold compensating controls even for providers it cannot realistically replace.
Start with the obligations that carry dates: incident notification readiness for your prudential regulator, breach reporting under the privacy statutes that apply to you, and the evidence your next exam or insurance renewal will request. From there, most credit unions sequence access reviews and retention cleanup, because those two controls shrink both the likelihood and the size of the incident scenarios that dominate the sector.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What's the difference between data privacy and cybersecurity?
- Do you need an incident response plan, and what should it include?
- What should I do after a data breach?
- VPO vs vCISO: do you need one, the other, or both?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program
- Building a Third-Party Vendor Risk Assessment Program That Scales
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.