№ 347 Compliance

PIPEDA and the shared brokerage inbox: the privacy risk nobody actually assigned.

A shared login that every assistant and part-time processor has used at some point isn't a workflow shortcut — it's a documentation gap waiting to become a privacy incident. Here's what PIPEDA actually requires, and the fix that doesn't slow anyone down.

Compliance 6 min read By the Treadstone Associates team · Canada Updated 2026-07

Key takeaways

  • PIPEDA's accountability and safeguards principles require limiting access to personal information to those who genuinely need it — a shared login with no individual accountability works against both.
  • Alberta, British Columbia, and Quebec have their own private-sector privacy laws deemed substantially similar to PIPEDA, so within those provinces it may be the provincial law — not PIPEDA itself — doing the governing, though the practical standard is comparable.
  • Every breach of security safeguards must be logged and kept for at least 2 years, whether or not it meets the threshold for reporting to the Privacy Commissioner — a shared inbox with no access log makes that requirement almost impossible to satisfy honestly.
  • The fix isn't a new privacy policy — it's individual logins with an offboarding checklist, which most email and CRM platforms already support at no extra cost.

Ask most brokerage owners who has access to the main client inbox, and the honest answer is often “everyone who's ever worked here, including a couple of people who don't anymore.” It's not malicious — it's the path of least resistance when onboarding a new assistant felt more urgent than setting up individual access.

It's also one of the most common, least discussed privacy exposures in a small brokerage, and it sits squarely inside obligations the brokerage already has under PIPEDA — or the provincial equivalent, depending where you operate.

01 · Why do shared inboxes become the default in a small brokerage?

It's almost always a speed decision, not a policy one. A new hire needs to see client emails on day one, a shared login already exists, and setting up individual access with proper permissions feels like a task for later. Later rarely comes, and the login outlives several staff changes.

The documents flowing through that inbox — income statements, bank statements, SIN-bearing tax documents, credit reports — are exactly the category PIPEDA treats as sensitive personal information requiring proportionate safeguards, which makes the shared-login shortcut a bigger exposure than it looks.

02 · What does PIPEDA actually require about who can access client information?

Two of PIPEDA's ten fair information principles are directly relevant. Accountability means an organization remains responsible for personal information under its control, including who inside the organization can see it. Safeguards means protecting personal information with security appropriate to its sensitivity — financial and identity documents sit at the higher end of that scale.

Where a shared login usually falls short of both principles: there's no way to say who actually accessed a given client's file at a given time, and access isn't limited to people who currently need it — it's limited to people who ever had the password. Alberta, British Columbia, and Quebec each have their own private-sector privacy law deemed substantially similar to PIPEDA, so the specific statute governing a purely intra-provincial brokerage may be provincial rather than federal — but the standard for access control and safeguards is comparable across all of them, and PIPEDA still applies to any information that crosses a provincial or international border.

03 · What actually goes wrong with a shared inbox in practice?

Three failure patterns show up repeatedly:

  • A former employee's access is never revoked, because revoking “the inbox” means changing a password everyone still uses, which nobody wants to be the one to break.
  • Forwarding rules quietly set up by a past staff member continue routing client documents to a personal address long after they've left.
  • When something does go wrong — a document sent to the wrong client, a file accessed by someone with no reason to be in it — there's no access log to determine what actually happened, which turns a containable incident into an open question.

04 · What's the practical fix, without slowing the team down?

Individual logins with role-based access, not a shared password. Every major email and CRM platform used by Canadian brokerages supports this at no meaningful extra cost or friction — the barrier is almost always inertia, not technical limitation.

Pair it with two habits: an offboarding checklist that revokes access the day someone leaves, not whenever someone remembers to, and a quarterly access review that asks a simple question — does everyone who currently has access still need it?

Documented access, not shared passwords

File handling that holds up if something goes wrong.

Treadstone's fulfillment associates work inside individually-logged systems, not shared logins — so client documents have a clear, defensible access trail from intake to close. Talk to us about how that works.

05 · What has to happen if a privacy incident actually occurs?

PIPEDA's mandatory breach reporting rule requires notifying the Privacy Commissioner and affected individuals as soon as feasible when a breach creates a real risk of significant harm — considering the sensitivity of the information and the likelihood of misuse. But the record-keeping duty is broader than the reporting duty: every breach of security safeguards must be logged, whether or not it clears the reporting threshold, and those records must be kept for a minimum of 2 years and produced to the Commissioner on request.

That's the requirement a shared, unlogged inbox makes almost impossible to meet honestly — you can't document who accessed what when there's no individual access trail to begin with.

Frequently asked questions

This article is general information to help you scale — not a substitute for tailored advice on your specific business, licensing, or compliance obligations. All figures are illustrative examples for planning purposes; actual costs vary by province, market, and brokerage.

Related Reading

Keep going down the rabbit hole.

All articles