New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Fintech & financial services
Privacy & Security for Payment Processors & PayFacs
Payment processors and PayFacs answer to more overseers than almost any other Canadian business: the Bank of Canada under the RPAA, FINTRAC as a money services business, card brands through PCI DSS v4.0.1, and privacy regulators watching cardholder and merchant data. Privacy Horizon helps Canadian PSPs build the frameworks, evidence and named accountability those overseers expect — usually starting when registration lands, a sponsor opens due diligence, or a big merchant asks for proof.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Registered payment service providers — gateways, ISO/PayFac hybrids and payout platforms now supervised by the Bank of Canada. Since September 8, 2025 you must maintain a risk-management and incident-response framework, safeguard end-user funds, and file an annual report by March 31. We turn those obligations into documents and routines your senior officer can actually approve.
PayFacs and ISVs with embedded payments that onboard sub-merchants on acquirer APIs. Your sponsor flows OSFI B-10 third-party expectations down to you, and PCI DSS treats you as a service provider — SAQ D-Service Provider or a full ROC — not a merchant. We help you carry both without stalling merchant growth.
Billing SaaS and payout companies moving money over Interac e-Transfer aggregators or EFT batches to the ACSS, often with FINTRAC MSB registration in the mix. You hold merchant KYB files, settlement instructions and fund balances that attackers and regulators both prize.

Services
Privacy & security services for payment processors & payfacs
Each service below is scoped for how payment processors & payfacs actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Payment Processors & PayFacs
vCISO for payment processors and PayFacs: executive security leadership for RPAA frameworks, PCI DSS v4 programs and sponsor-bank due diligence.
Virtual Privacy Officer
Virtual Privacy Officer for Payment Processors & PayFacs
Virtual Privacy Officer for payment processors and PayFacs: Law 25 designation, PIPEDA breach duties and merchant data governance for Canadian PSPs.
Penetration Testing
Penetration Testing for Payment Processors & PayFacs
Penetration testing for payment processors and PayFacs: CDE and segmentation testing built for PCI DSS v4 and sponsor-bank due diligence.
Incident Response Planning
Incident Response Planning for Payment Processors & PayFacs
Incident response plan for payment processors and PayFacs: one runbook for Bank of Canada 'without delay' notices, OPC reports and PCI 12.10 duties.
Privacy & Security Policy Development
Privacy & Security Policy Development for Payment Processors & PayFacs
Policy development for payment processors and PayFacs: the RPAA framework, safeguarding-of-funds and retention documents regulators want to see.
Privacy & Security Training
Privacy & Security Training for Payment Processors & PayFacs
Privacy and security training for payment processors and PayFacs: PCI awareness for PAN-handling staff and anti-insider modules for KYB access.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Payment Processors & PayFacs
Vendor security reviews for payment processors and PayFacs: annual RPAR third-party assessments, KYB vendor scrutiny and merchant questionnaire support.
SOC 2 Readiness
SOC 2 Readiness for Payment Processors & PayFacs
SOC 2 readiness for payment processors and PayFacs: the report platform partners want when a PCI AOC alone doesn't cover uptime and broader data handling.
ISO 27001 Readiness
ISO 27001 Readiness for Payment Processors & PayFacs
ISO 27001 readiness for payment processors and PayFacs expanding into international acquirer programs, with a control set built to overlap with PCI DSS.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Payment Processors & PayFacs
AI-PIA for payment processors and PayFacs: fraud-scoring and merchant underwriting models reviewed against Law 25's automated-decision rules.
What you hold
What a payments company holds that nobody else does
A processor's crown jewels go well beyond a customer list. Five data sets deserve deliberate protection because losing any one ends relationships with sponsors, merchants or the Bank of Canada.
Cardholder data and the tokenization vault
Full PAN and track-equivalent data remain in PCI scope even when tokenized. The vault, HSMs and any P2PE terminal estate connected to acquirers like Moneris, Global Payments or Elavon form the CDE that every assessment revolves around.
Merchant KYB files
Articles of incorporation, beneficial-owner IDs, banking details and void cheques collected at sub-merchant onboarding are personal information about real people — business owners — protected by PIPEDA and Quebec Law 25 as much as any consumer record.
End-user fund balances and the ledger
Money held for merchants and payees must be safeguarded under the RPAA through a trust account or an insurance or guarantee arrangement, and the ledger recording those balances has to stay accurate and tamper-evident.
Settlement and payout instructions
Bank account changes and payout routing are prime targets for business email compromise. One altered settlement instruction moves real money to a criminal before anyone notices the merchant wasn't paid.
Chargeback, dispute and fraud-score records
Representment files and ML fraud scores pair transaction detail with behavioural inference about identifiable people, raising confidentiality stakes and automated-decision transparency questions.
Regulatory map
The rulebook stacked on Canadian payment companies
No neighbouring fintech carries this exact stack: supervision by the central bank, AML duties, card-brand contract law and general privacy statutes all at once.
RPAA registration and Bank of Canada supervision
PSPs performing payment functions for end users in Canada must register with the Bank of Canada; banks and credit unions are excluded. The Bank can issue notices of violation with administrative monetary penalties and expects material-impact incidents notified without delay.
Retail Payment Activities Regulations (SOR/2023-229)
The RPAR spells out what your framework must contain: objectives, senior-officer and board approval, annual review, third-party service provider assessments, testing and periodic independent review — plus 5 business days' notice of significant changes.
FINTRAC money services business obligations
Settling invoices, transferring funds or doing foreign exchange makes you an MSB: registration, a 5-element compliance program, KYC, record keeping, STR/LCTR/EFTR reporting and biennial effectiveness reviews.
PCI DSS v4.0.1 as a service provider
The standard explicitly covers processors, acquirers and service providers, not just merchants. Version 3.2.1 retired March 31, 2024, and every future-dated v4 requirement became mandatory March 31, 2025 — including the payment-page script controls aimed at skimming.
FCAC Code of Conduct for the Payment Card Industry
The revised Code, effective October 30, 2024, expanded beyond issuers and acquirers to downstream participants — capturing processors and payment facilitators — with complaint-handling and disclosure duties toward merchants.
PIPEDA, Law 25 and Alberta PIPA
PIPEDA governs your commercial handling of personal information and its cross-border flows, with mandatory OPC and individual notification for breaches posing a real risk of significant harm. Quebec Law 25 layers on a designated privacy officer, PIAs, an incident register and penalties reaching $10M or 2% of worldwide turnover.
What goes wrong
Attack patterns that single out payment rails
Incidents in this sector rarely look like generic ransomware. They exploit how processors concentrate card data, money movement and merchant trust in one place.
Long-dwell gateway compromise
Slim CD, a gateway serving U.S. and Canadian merchants, disclosed intruder access running from August 2023 to June 2024 that exposed roughly 1.7 million cards — proof that carding attacks can sit inside a payment platform for months.
Insiders mining transaction tooling
At Shopify in Ottawa, two rogue support employees used internal order tooling to harvest transactional records of about 200 merchants in September 2020. Support staff with broad lookup rights are a standing exposure for any payments operation.
Payout redirection and portal credential stuffing
BEC aimed at settlement instructions and stuffing attacks on merchant portals convert stolen credentials directly into cash. The OSFI/FCAC report on AI notes fraud across the financial sector is rising and getting harder to detect.
Checkout skimming and script injection
Magecart-style script tampering on payment pages is common enough that PCI DSS v4 built dedicated requirements around inventorying and integrity-checking checkout scripts, now in force.
Outages that become regulatory incidents
Under the RPAA, a service disruption with material impact on end users is itself a reportable incident to the Bank of Canada — availability failures now carry supervisory consequences, not just SLA credits.
When organisations call us
Moments that bring processors and PayFacs to us
Engagements here almost never start with abstract risk appetite. They start with a date, a questionnaire or a deal on hold.
RPAA milestones
Registration opened November 2024, framework duties bit on September 8, 2025, and the annual report lands every March 31. Each milestone exposes gaps between what was filed and what exists.
Sponsor-bank and acquirer due diligence
Onboarding with a sponsor means security schedules shaped by OSFI B-10 third-party expectations. Weak answers slow the deal or attach conditions you will be audited against later.
A merchant or platform wants attestation
Larger merchants and platform partners increasingly refuse to sign until they see a PCI AOC, a SOC 2 report, or both. Sales teams feel this before security teams do.
The PCI v4 uplift
Fifty-one future-dated requirements became mandatory on March 31, 2025. Processors that validated comfortably under v3.2.1 are finding new obligations across authentication, scripts and monitoring.
Fraud spikes and forensic mandates
A card brand or processor-mandated forensic investigation after a fraud spike forces rapid, credible answers about containment, scope and remediation.
Payment Processors & PayFacs: privacy & security questions, answered
Registration turns on whether you perform payment functions for end users in Canada, not on who holds the settlement account. Banks and credit unions are excluded, but that exclusion does not extend to the PSPs riding on their rails. Most gateways, PayFacs and payout platforms fall in scope and should have registered when the window opened in November 2024; if your status is unclear, get a scoping analysis before the Bank of Canada raises it.
Often yes — they are separate regimes with different tests. FINTRAC looks at whether you settle invoices, transfer funds or do foreign exchange, which makes you a money services business with registration, a 5-element compliance program, KYC, record keeping and STR/LCTR/EFTR reporting, plus biennial effectiveness reviews. The RPAA looks at retail payment functions. Many processors sit under both regimes, which share evidence but not obligations.
No. Cardholder data remains in scope even when tokenized — the vault, the detokenization paths and the systems that touch them all count. Tokenization is a strong scope-reduction tool, but it does not remove your duties as a service provider under PCI DSS v4.0.1, and assessors will trace exactly where PAN can still appear.
Under the RPAA it can be a reportable one. Incidents with material impact on end users — including availability failures, not just breaches — must be notified to the Bank of Canada and affected parties without delay. Processors therefore need incident criteria that weigh merchant and payee impact, not only data confidentiality, and a decision path that works during peak retail volume.
PIPEDA applies to your commercial activity and cross-border data flows, with mandatory reporting to the OPC and affected individuals when a breach creates a real risk of significant harm, plus 24-month record keeping. For Québec merchants or cardholders, Law 25 adds a designated privacy officer, PIAs before sending data outside the province, and an incident register; Alberta PIPA s. 34.1 has its own Commissioner reporting. Beneficial-owner details in KYB files are personal information too.
Payments Canada has slated the Real-Time Rail to launch in Q4 2026 with a PSP participation guide, bringing direct exposure to payment-system rules. If real-time payments are on your roadmap, build your RPAA framework, third-party assessments and incident processes now so RTR participation extends an existing program instead of forcing a second compliance build.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What's the difference between data privacy and cybersecurity?
- How do we prepare for a customer security questionnaire?
- VPO vs vCISO: do you need one, the other, or both?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.