New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Fintech & financial services
Privacy & Security for Online Lenders & BNPL Providers
Online lenders and BNPL providers hold exactly what identity thieves want: SINs on applications, full bureau files, KYC documents and PAD banking details. Privacy Horizon builds privacy and security programs for Canadian lending teams that stand up to bank-partner due diligence, Equifax and TransUnion membership audits, and Quebec's automated-decision rules. Most engagements start when a funding partner, merchant platform or regulator asks a question the team cannot yet answer.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with instalment lenders, BNPL checkout providers, payday and high-cost lenders moving online, SMB revenue-based lenders, and private and mortgage lenders across Canada, typically between 15 and 400 staff. The common thread: an adjudication engine making credit decisions on bureau and bank-statement data, and no in-house privacy or security executive.
Buyers are usually the founder, COO, Chief Risk Officer or compliance manager. Something external has forced the issue: a warehouse-line lender flowing down OSFI B-10 due diligence, a merchant platform demanding SOC 2 before embedding your checkout SDK, or a declined applicant escalating to the OPC or CAI.
The January 1, 2025 drop of the criminal interest rate to 35% APR pushed many lenders to rebuild products and systems under regulator attention. Teams re-platforming an LOS or LMS in that climate need privacy and security decisions made correctly the first time.

Services
Privacy & security services for online lenders & bnpl providers
Each service below is scoped for how online lenders & bnpl providers actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Online Lenders & BNPL Providers
vCISO for online lenders and BNPL: security leadership that clears bank-partner B-10 reviews, bureau audits and merchant diligence without a full-time hire.
Virtual Privacy Officer
Virtual Privacy Officer for Online Lenders & BNPL Providers
Virtual Privacy Officer for online lenders and BNPL: a named privacy lead for credit files, bureau data, checkout consent and Law 25 duties in Quebec.
Penetration Testing
Penetration Testing for Online Lenders & BNPL Providers
Penetration testing for online lenders and BNPL: borrower portals, lending APIs and checkout SDKs tested against account takeover before fraudsters try first.
Incident Response Planning
Incident Response Planning for Online Lenders & BNPL Providers
Incident response planning for online lenders and BNPL: a rehearsed playbook for PAD leaks, LMS ransomware and bank-partner notice deadlines.
Privacy & Security Policy Development
Privacy & Security Policy Development for Online Lenders & BNPL Providers
Privacy and security policy development for online lenders and BNPL: retention, consent, adverse-action and merchant data-sharing policies that hold up.
Privacy & Security Training
Privacy & Security Training for Online Lenders & BNPL Providers
Role-based privacy and security training for online lenders and BNPL: underwriters, collections agents and fraud teams handling bureau and PAD data.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Online Lenders & BNPL Providers
Vendor security review for online lenders and BNPL: vetting aggregators, identity vendors, LOS providers and merchant BNPL agreements before they go live.
SOC 2 Readiness
SOC 2 Readiness for Online Lenders & BNPL Providers
SOC 2 readiness for online lenders and BNPL: closing gaps around the LOS, decision engine and bureau access before a partner asks for a report.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Online Lenders & BNPL Providers
AI-PIA for online lenders and BNPL: documenting how a credit-adjudication model uses personal data and meets Law 25's automated-decision duties.
What you hold
The borrower data a lending operation has to defend
A loan book is a concentration of the most marketable personal information in Canada. Every record below has a resale value on the fraud market and a regulator watching how you hold it.
Credit applications and SINs
Applications capture income, employer and often a SIN, whether or not the borrower ever funds. Declined files pile up in the LOS and carry the same breach consequences as active loans.
Bureau files and tradelines
Equifax and TransUnion pulls land full credit histories in your decision engine. Membership agreements make you contractually accountable for how that bureau data is stored, accessed and destroyed.
Bank-statement data from aggregators
Flinks and Plaid-style connections pull months of transaction history for income verification. That is a live map of a borrower's financial life sitting in your underwriting warehouse.
KYC identity documents
Government ID scans and selfies collected by identity-verification vendors are a synthetic-identity kit if exfiltrated, and they tend to persist long after onboarding ends.
PAD banking details and payment runs
Pre-authorized debit records hold institution, transit and account numbers for your whole book. A leak here exposes borrowers to direct account fraud, not just spam.
Collections notes and adverse-action reasons
Dialer and CRM systems accumulate hardship details, dispute history and recorded decline reasons — sensitive context that stings most if it ever becomes public.
Regulatory map
The rulebook stacked on top of Canadian lending
Lenders answer to criminal law on pricing, provincial licensing on conduct, federal and Quebec privacy law on data, and bank-partner contracts that import OSFI expectations. Each layer has its own auditor.
Criminal Code interest cap
Since January 1, 2025 the criminal rate sits at 35% APR, down from roughly 48% EAR, with payday costs capped at $14 per $100 in provinces with payday regimes. The change forced product and system rework and invited fresh regulator scrutiny.
Provincial payday and high-cost licensing
Ontario's Payday Loans Act, 2008 requires payday lenders to be licensed; Alberta issues its own payday licences and BC licenses high-cost credit granting through Consumer Protection BC. Licence conditions reach into your record-keeping.
PIPEDA on every pull and transfer
Lending is commercial activity, so PIPEDA governs bureau pulls, aggregator access and the US-cloud hosting most lending stacks rely on, with real-risk breaches reported to the OPC as soon as feasible.
Quebec Law 25 and automated decisions
Section 12.1 requires telling applicants when a decision such as an auto-decline rests exclusively on automated processing, and explaining the principal factors on request. AMPs run to $10M or 2% of turnover, penal fines to $25M or 4%.
FINTRAC for the mortgage sector
Mortgage lenders, brokers and administrators are FINTRAC reporting entities with published sector guidance, adding AML program, reporting and record duties on top of privacy law.
OSFI B-10 flowing down from bank partners
Warehouse-line and securitization partners are federally regulated, so their third-party risk obligations become your due-diligence questionnaire, your audit clause and your incident-notice deadline.
Alberta and BC PIPA in the mix
Alberta's PIPA s. 34.1 makes breach reporting mandatory, and BC's OIPC publishes notification guidance lenders are expected to follow when western borrowers are affected.
What goes wrong
Incident patterns that have already hit lending
None of these are hypothetical. Each pattern below comes from a documented Canadian investigation or a campaign that struck the financial sector directly.
Insiders selling borrower data
In the Desjardins breach affecting 9.7 million people, the malicious employee reportedly sold personal information to a private lender. The lending market itself creates illicit demand for exactly the data you hold.
Bureau-connected compromise
Equifax 2017 combined an unpatched Struts server, poor segmentation and indefinite retention, exposing Canadians' SINs through a US parent. The OPC's finding is the reference case for anyone wired into a bureau.
Synthetic identity against the decision engine
OSFI and FCAC report application fraud rising and getting harder to detect as adjudication automates. Fabricated identities built from breached KYC data target the very speed BNPL sells.
Account takeover on borrower portals
Portals holding bank credentials and PAD details draw credential-stuffing at scale. A hijacked borrower account can redirect funding or expose linked banking data in minutes.
File-transfer and vendor channels
The 2023 MOVEit campaign compromised organizations including Nova Scotia's government, affecting roughly 100,000 people — the canonical warning for lenders moving statement files to service providers.
Payout redirection through BEC
Funding disbursements and collections settlements move on tight timelines, which is what business email compromise exploits: one convincing change-of-account request during a busy payment run.
When organisations call us
The moments lending teams pick up the phone
Few lenders buy privacy and security work on a calendar. A counterparty, insurer or regulator usually sets the deadline.
A warehouse line hangs on due diligence
A bank funding partner opens B-10-style third-party review before extending or renewing the facility, and the questionnaire asks for artifacts nobody has written yet.
A bureau audits your membership
Equifax or TransUnion invokes the data-security addendum and wants evidence of access controls, retention practices and safeguards around their files in your systems.
A merchant platform wants SOC 2
The e-commerce partnership that would embed your BNPL SDK in thousands of checkouts stalls until a report or a credible readiness story exists.
The 35% cap forced a rebuild
Repricing and re-platforming after the criminal-rate change touched the LOS, the LMS and the decision engine at once, and someone asked who assessed the privacy impact.
Cyber insurance gets harder to renew
After fraud losses across the sector, the renewal application demands MFA, tested response plans and vendor oversight the team cannot yet evidence.
A declined applicant escalates
A complaint about an auto-decline lands at the OPC or CAI, and the first question is whether the applicant was told the decision was automated.
Online Lenders & BNPL Providers: privacy & security questions, answered
Yes. Your payday or high-cost licence governs the conduct and cost of lending, not the data. Lending is commercial activity, so PIPEDA applies to your handling of applications, bureau files and payment records, and Alberta and BC's private-sector laws apply to borrowers in those provinces. Holding a provincial licence adds obligations; it never subtracts privacy law.
Law 25 attaches immediately: a designated privacy officer, PIAs before new systems and before sending data outside Quebec, confidentiality-incident reporting to the CAI, and the s. 12.1 duty to disclose exclusively automated decisions and explain their principal factors on request. With administrative penalties reaching $10M or 2% of worldwide turnover, Quebec volume deserves deliberate onboarding, not accidental drift.
A SIN is optional but commonly collected to improve bureau matching. Collecting it is lawful with consent, but it raises the stakes: you must be able to justify the purpose, restrict who can see it, and destroy it on schedule. Many lenders reduce exposure by making the field genuinely optional and keeping SINs out of collections systems and data warehouses entirely.
Bureau audits work from the data-security addendum you signed: who can query the bureau, how credentials are controlled, where files land, how long they persist and how they are destroyed. Preparation means mapping every system touching bureau data, tightening decision-engine access and documenting retention. The OPC's Equifax finding shows what regulators conclude when safeguards, retention and accountability fail together.
Because OSFI's third-party risk guideline makes you their problem. A federally regulated warehouse lender must assess and monitor material third parties, so its obligations flow down to you as questionnaires, audit rights, incident-notification clauses and remediation demands. Answer the first questionnaire with evidence you can reuse in every future facility negotiation.
Under PIPEDA's breach regulations, report to the OPC as soon as feasible once a breach poses real risk of significant harm, notify affected borrowers, and keep records of every breach for 24 months. Quebec adds CAI reporting under Law 25, and Alberta's PIPA s. 34.1 makes reporting mandatory there. Bank partners and bureaus usually impose contractual notice on top, often tighter than statute.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- VPO vs vCISO: do you need one, the other, or both?
- How do we prepare for a customer security questionnaire?
- What should I do after a data breach?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- Building a Third-Party Vendor Risk Assessment Program That Scales
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- How Canadian Startups Should Sequence SOC 2 Around Their First Enterprise Deal
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.