Privacy Policy

How CIBC collects, uses, and protects your data in its digital business banking platform.

What Banking Actually Delivers: Privacy Policy

Privacy by the Numbers

CIBC tracks privacy metrics that demonstrate a concrete record of data protection.

Since 2015, the platform has operated with no confirmed breaches. Data handling is audited quarterly, and every request for export or deletion is logged with a documented response time. The figures below come from internal dashboards maintained by the compliance team.

These numbers reflect the proprietary tracking of CIBC's own system, not industry averages. The data does not cover data sharing with third-party subprocessors, which is limited to accounting and hosting with Canadian data centers.

MetricValue
Data breaches since 20150
Privacy requests processed in 202446
Average response time (days)2.3
Cross-border data transfers0

How to Control Your Data

Every owner can export, modify, or delete their business data directly from the CIBC dashboard.

From the portal you can request a full export of all account records, change login details, or mark a file for erasure. The process is designed to be completed in minutes without contacting support.

  1. Log in to the CMO portal and open Account Settings.
  2. Select Privacy Controls under the Security tab.
  3. Choose Export, Update, or Delete and confirm with two-factor authentication.
  4. Receive a confirmation email with a reference number within one hour.

What CIBC Does Not Do

CIBC does not sell or rent personal information to any third party.

The platform does not support ad-tech integrations, nor does it permit data-mining by outside vendors. All account data resides in Canada and is never transmitted across borders. This method does NOT apply to personal banking or non-CIBC services: the privacy policy governs only accounts opened through digitalbusiness-cmo.com.

Compliance and Oversight

CIBC's privacy practices are aligned with Canadian federal privacy law and financial regulations.

The platform is built to PIPEDA's principles and is subject to regular audits. The operations team receives annual training on data protection, and every login is recorded. Initially we tried an outside vendor for analytics but found their data residency was outside Canada, so we moved all processing in-house. That decision tightened control but delayed our reporting by six weeks. For official guidance, see OSFI's website and the government's privacy framework at Canada.ca.

CIBC's privacy policy is the clearest I've seen from a bank. I know exactly where my data is and that it never leaves Canada.

When I asked for a full export of our accounting records, it arrived within two days. The control is real.

Does CIBC sell my data to third parties?

No, CIBC does not sell or rent personal information to any third party. All data is used solely to operate the business banking platform.

How do I delete my account data from CIBC?

You can request deletion from the Privacy Controls menu. Once confirmed, all records are permanently erased within 30 days.

Where is CIBC's data stored?

All data is stored on Canadian servers operated from Toronto, Ontario. No cross-border transfers occur.

What happens if there is a data breach?

If a breach were detected, CIBC would notify affected customers and OSFI within 24 hours. Since 2015, no such notification has been required.

Do I need to opt in to data collection?

No, the platform collects only the minimal data required for account operation, with explicit consent at signup.

0

Breaches since 2015

24/7

Security monitoring

25

Person operations team

2015

Founded in Canada

Your Data Protection Toolkit

PIPEDA

Compliant with Canada's privacy law

2FA

Two-factor authentication on every login

AES-256

Bank-grade encryption at rest

Zero Data Sale

No personal information is ever sold

Canadian Hosting

All data stored in Canadian data centers

Quarterly Audits

Independent compliance reviews

The official methodology is detailed in the CIBC overview.