PIPEDA is Canada's federal private-sector privacy law, and it applies to a mortgage brokerage the same way it applies to any commercial organization that collects personal information in the course of business. The core requirement is deceptively simple to state and easy to under-implement in practice: the knowledge and consent of the individual are required for the collection, use, or disclosure of their personal information, subject to narrow exceptions that rarely apply to an ordinary mortgage file.
For a mortgage file specifically, this covers everything from the income documents and identification gathered at intake, through the credit report pulled during underwriting, to the file shared with a lender, and potentially an outsourced fulfillment provider, to get the deal closed. Each of those is a collection, use, or disclosure PIPEDA has a view on — not a single event, but a chain of them running through the life of the file.
Consent under PIPEDA has to be meaningful, which means a client needs a genuine understanding of what's being collected and roughly what it will be used for — not a technically-present signature on a document nobody walked them through. This doesn't require a lengthy legal disclosure recited at the start of every client relationship; it can be built into the ordinary flow of the intake conversation, explained in plain language at the point information is actually being requested.
The practical standard worth aiming for: a client should never be surprised, months into a relationship, to learn that their information was shared with a party they didn't know was involved. If a client would reasonably say “I didn't realize that was going to happen” about a specific disclosure, that's a sign the consent obtained beforehand wasn't meaningful enough, regardless of what a signed form technically says.
Sharing a client's file with a lender is the most obvious disclosure in a mortgage transaction, and clients generally understand and expect it as part of what a broker does. Less obvious, and more important to be explicit about, are disclosures a client might not automatically anticipate: an underwriter or insurer reviewing the file as part of the approval process, or a third-party fulfillment provider assembling or processing the file on the brokerage's behalf rather than the brokerage's own staff doing it directly.
None of these arrangements are prohibited by PIPEDA — outsourcing file processing to a specialist provider is a normal and legitimate way to run a brokerage. What PIPEDA requires is that the client understands, before the file moves forward, that this is part of how their information will be handled, so the disclosure doesn't come as a surprise if the client later asks who's seen their documents.
If a client's file is exposed — through a hacked system, a misdirected email, a lost device, or any other incident — PIPEDA requires the brokerage to assess whether the breach creates a real risk of significant harm to the affected individual. That assessment weighs two things: the sensitivity of the information involved (financial records, income documents, and identification are all sensitive by nature) and the probability that the exposed information will actually be misused, considering who accessed it, how long it was exposed, whether there's evidence of malicious intent, and whether the data was encrypted.
If that assessment concludes there's a real risk of significant harm — which will usually be the case for a breach involving mortgage documents, income statements, or identification — the brokerage must report the breach to the Office of the Privacy Commissioner and notify the affected client as soon as feasible. “Significant harm” in this context includes identity theft, financial loss, and damage to a client's credit standing, all of which are realistic consequences of a mortgage file being exposed.
Separate from the reporting decision, PIPEDA requires a brokerage to keep a record of every breach it becomes aware of — not just the ones serious enough to clear the real-risk-of-significant-harm threshold and get reported. This record has to contain enough detail that the Privacy Commissioner could review it later and verify the brokerage actually assessed the risk properly, rather than simply deciding informally that a given incident didn't need reporting.
In practice, this means a minor incident — a document accidentally sent to the wrong internal recipient, caught and corrected within minutes — still deserves a short written note describing what happened and why it was assessed as low-risk, even though it never gets reported externally. A brokerage that only documents the breaches it decides to report has an incomplete record if the Commissioner ever asks to see the full picture.
A brokerage outsources a portion of its file processing to a third-party fulfillment provider, without ever mentioning this to clients. A client later finds out and is upset that people outside the brokerage handled their documents. What's the compliance issue here?
PIPEDA doesn't prohibit outsourcing — it's a normal, legitimate business arrangement — but it does require that a disclosure like this be covered by meaningful consent obtained before the fact, not discovered by the client afterward. A client who's surprised by a disclosure they didn't know was coming is exactly the scenario meaningful consent is supposed to prevent. This is a privacy and consent issue about who saw the client's information, which is squarely PIPEDA's territory, not CASL's — CASL governs marketing messages, not file-processing arrangements.
The intro and first module are free to read. Add your name and email once and the rest of this course opens — along with every other course on the site. No card, no trial.
Already unlocked on another device?