When I talk about data sharing, what I mean very specifically are very specific data elements that are shared between very specific parties. I think there are two elements from a legal perspective to focus on. One of them was mentioned earlier about having a clear basis to process data for fraud. That exists in PIPEDA today.
My experience with negotiating data-sharing agreements as an FI at a fintech and now at Interac has been that we focus very much on consent as the core of our focus, and that re-emphasizes that grounds to process data is important.
The other one is around safe harbour provisions for that intelligence sharing. They exist in other jurisdictions for financial crimes sharing. Why I think it's so important is, in my experience that I just mentioned, our participants really take very seriously their responsibility for data, and they will only share it if they feel the risk is low or acceptable. That safe harbour provision encourages the type of intelligence sharing that we think is key if we're going to stop the problem at the outset.
