Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Fintech & financial services

Privacy & Security for Payment Processors & PayFacs

Payment processors and PayFacs answer to more overseers than almost any other Canadian business: the Bank of Canada under the RPAA, FINTRAC as a money services business, card brands through PCI DSS v4.0.1, and privacy regulators watching cardholder and merchant data. Privacy Horizon helps Canadian PSPs build the frameworks, evidence and named accountability those overseers expect — usually starting when registration lands, a sponsor opens due diligence, or a big merchant asks for proof.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Registered payment service providers — gateways, ISO/PayFac hybrids and payout platforms now supervised by the Bank of Canada. Since September 8, 2025 you must maintain a risk-management and incident-response framework, safeguard end-user funds, and file an annual report by March 31. We turn those obligations into documents and routines your senior officer can actually approve.

PayFacs and ISVs with embedded payments that onboard sub-merchants on acquirer APIs. Your sponsor flows OSFI B-10 third-party expectations down to you, and PCI DSS treats you as a service provider — SAQ D-Service Provider or a full ROC — not a merchant. We help you carry both without stalling merchant growth.

Billing SaaS and payout companies moving money over Interac e-Transfer aggregators or EFT batches to the ACSS, often with FINTRAC MSB registration in the mix. You hold merchant KYB files, settlement instructions and fund balances that attackers and regulators both prize.

Two data analysts Working on data analysis dashboard for business strategy

Services

Privacy & security services for payment processors & payfacs

Each service below is scoped for how payment processors & payfacs actually operate — their systems, their regulators and the reviews they face.

What you hold

What a payments company holds that nobody else does

A processor's crown jewels go well beyond a customer list. Five data sets deserve deliberate protection because losing any one ends relationships with sponsors, merchants or the Bank of Canada.

Cardholder data and the tokenization vault

Full PAN and track-equivalent data remain in PCI scope even when tokenized. The vault, HSMs and any P2PE terminal estate connected to acquirers like Moneris, Global Payments or Elavon form the CDE that every assessment revolves around.

Merchant KYB files

Articles of incorporation, beneficial-owner IDs, banking details and void cheques collected at sub-merchant onboarding are personal information about real people — business owners — protected by PIPEDA and Quebec Law 25 as much as any consumer record.

End-user fund balances and the ledger

Money held for merchants and payees must be safeguarded under the RPAA through a trust account or an insurance or guarantee arrangement, and the ledger recording those balances has to stay accurate and tamper-evident.

Settlement and payout instructions

Bank account changes and payout routing are prime targets for business email compromise. One altered settlement instruction moves real money to a criminal before anyone notices the merchant wasn't paid.

Chargeback, dispute and fraud-score records

Representment files and ML fraud scores pair transaction detail with behavioural inference about identifiable people, raising confidentiality stakes and automated-decision transparency questions.

Regulatory map

The rulebook stacked on Canadian payment companies

No neighbouring fintech carries this exact stack: supervision by the central bank, AML duties, card-brand contract law and general privacy statutes all at once.

RPAA registration and Bank of Canada supervision

PSPs performing payment functions for end users in Canada must register with the Bank of Canada; banks and credit unions are excluded. The Bank can issue notices of violation with administrative monetary penalties and expects material-impact incidents notified without delay.

Primary source →

Retail Payment Activities Regulations (SOR/2023-229)

The RPAR spells out what your framework must contain: objectives, senior-officer and board approval, annual review, third-party service provider assessments, testing and periodic independent review — plus 5 business days' notice of significant changes.

Primary source →

FINTRAC money services business obligations

Settling invoices, transferring funds or doing foreign exchange makes you an MSB: registration, a 5-element compliance program, KYC, record keeping, STR/LCTR/EFTR reporting and biennial effectiveness reviews.

Primary source →

PCI DSS v4.0.1 as a service provider

The standard explicitly covers processors, acquirers and service providers, not just merchants. Version 3.2.1 retired March 31, 2024, and every future-dated v4 requirement became mandatory March 31, 2025 — including the payment-page script controls aimed at skimming.

Primary source →

FCAC Code of Conduct for the Payment Card Industry

The revised Code, effective October 30, 2024, expanded beyond issuers and acquirers to downstream participants — capturing processors and payment facilitators — with complaint-handling and disclosure duties toward merchants.

Primary source →

PIPEDA, Law 25 and Alberta PIPA

PIPEDA governs your commercial handling of personal information and its cross-border flows, with mandatory OPC and individual notification for breaches posing a real risk of significant harm. Quebec Law 25 layers on a designated privacy officer, PIAs, an incident register and penalties reaching $10M or 2% of worldwide turnover.

Read our guide →

What goes wrong

Attack patterns that single out payment rails

Incidents in this sector rarely look like generic ransomware. They exploit how processors concentrate card data, money movement and merchant trust in one place.

  • Long-dwell gateway compromise

    Slim CD, a gateway serving U.S. and Canadian merchants, disclosed intruder access running from August 2023 to June 2024 that exposed roughly 1.7 million cards — proof that carding attacks can sit inside a payment platform for months.

    Source →

  • Insiders mining transaction tooling

    At Shopify in Ottawa, two rogue support employees used internal order tooling to harvest transactional records of about 200 merchants in September 2020. Support staff with broad lookup rights are a standing exposure for any payments operation.

    Source →

  • Payout redirection and portal credential stuffing

    BEC aimed at settlement instructions and stuffing attacks on merchant portals convert stolen credentials directly into cash. The OSFI/FCAC report on AI notes fraud across the financial sector is rising and getting harder to detect.

    Source →

  • Checkout skimming and script injection

    Magecart-style script tampering on payment pages is common enough that PCI DSS v4 built dedicated requirements around inventorying and integrity-checking checkout scripts, now in force.

  • Outages that become regulatory incidents

    Under the RPAA, a service disruption with material impact on end users is itself a reportable incident to the Bank of Canada — availability failures now carry supervisory consequences, not just SLA credits.

    Source →

When organisations call us

Moments that bring processors and PayFacs to us

Engagements here almost never start with abstract risk appetite. They start with a date, a questionnaire or a deal on hold.

  • RPAA milestones

    Registration opened November 2024, framework duties bit on September 8, 2025, and the annual report lands every March 31. Each milestone exposes gaps between what was filed and what exists.

  • Sponsor-bank and acquirer due diligence

    Onboarding with a sponsor means security schedules shaped by OSFI B-10 third-party expectations. Weak answers slow the deal or attach conditions you will be audited against later.

  • A merchant or platform wants attestation

    Larger merchants and platform partners increasingly refuse to sign until they see a PCI AOC, a SOC 2 report, or both. Sales teams feel this before security teams do.

  • The PCI v4 uplift

    Fifty-one future-dated requirements became mandatory on March 31, 2025. Processors that validated comfortably under v3.2.1 are finding new obligations across authentication, scripts and monitoring.

  • Fraud spikes and forensic mandates

    A card brand or processor-mandated forensic investigation after a fraud spike forces rapid, credible answers about containment, scope and remediation.

Payment Processors & PayFacs: privacy & security questions, answered

Registration turns on whether you perform payment functions for end users in Canada, not on who holds the settlement account. Banks and credit unions are excluded, but that exclusion does not extend to the PSPs riding on their rails. Most gateways, PayFacs and payout platforms fall in scope and should have registered when the window opened in November 2024; if your status is unclear, get a scoping analysis before the Bank of Canada raises it.

Often yes — they are separate regimes with different tests. FINTRAC looks at whether you settle invoices, transfer funds or do foreign exchange, which makes you a money services business with registration, a 5-element compliance program, KYC, record keeping and STR/LCTR/EFTR reporting, plus biennial effectiveness reviews. The RPAA looks at retail payment functions. Many processors sit under both regimes, which share evidence but not obligations.

No. Cardholder data remains in scope even when tokenized — the vault, the detokenization paths and the systems that touch them all count. Tokenization is a strong scope-reduction tool, but it does not remove your duties as a service provider under PCI DSS v4.0.1, and assessors will trace exactly where PAN can still appear.

Under the RPAA it can be a reportable one. Incidents with material impact on end users — including availability failures, not just breaches — must be notified to the Bank of Canada and affected parties without delay. Processors therefore need incident criteria that weigh merchant and payee impact, not only data confidentiality, and a decision path that works during peak retail volume.

PIPEDA applies to your commercial activity and cross-border data flows, with mandatory reporting to the OPC and affected individuals when a breach creates a real risk of significant harm, plus 24-month record keeping. For Québec merchants or cardholders, Law 25 adds a designated privacy officer, PIAs before sending data outside the province, and an incident register; Alberta PIPA s. 34.1 has its own Commissioner reporting. Beneficial-owner details in KYB files are personal information too.

Payments Canada has slated the Real-Time Rail to launch in Q4 2026 with a PSP participation guide, bringing direct exposure to payment-system rules. If real-time payments are on your roadmap, build your RPAA framework, third-party assessments and incident processes now so RTR participation extends an existing program instead of forcing a second compliance build.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.