Treadstone Associates
Ask an Expert · 3 min read

Can we store deal files in the cloud?

Yes — RECO doesn’t dictate the medium. PIPEDA is what actually governs how you do it.

Treadstone Associates · Updated 2026

Short answer

Nothing in RECO’s brokerage guidance requires paper files or an on-premise server. What travels with the file regardless of where it’s hosted is your PIPEDA accountability: federal guidance is explicit that “an organization that collects personal information from an individual is accountable for the personal information even when it is outsourced for processing to third-party providers” — so the vendor’s security is your due-diligence job, not a box you tick once.

RECO’s silence isn’t a gap you can exploit

The broker of record’s recordkeeping duty, per RECO’s own brokerage administration guidance, is described as “maintaining proper records, implementing effective compliance procedures, trust account management, monitoring advertising and trade documentation, and addressing any areas of non-compliance” — nothing there names a storage medium. Cloud storage isn’t itself the compliance problem; whether the records stay complete, accessible and under your control is.

What PIPEDA actually asks of you

The Office of the Privacy Commissioner’s own cloud computing guidance sets out what accountability actually requires: restricted access appropriate to the data’s sensitivity, encryption you understand well enough to know where data is exposed, a breach-notification clause with the vendor, and a real exit plan — “termination procedures permit the transfer of personal information back to the organization and require that the cloud provider securely delete all personal information.” It also flags a cross-border catch worth checking before you sign with a US-hosted platform: “personal information that is transferred to another country is subject to the laws of that jurisdiction,” and “no contract, no matter how well crafted, can override the laws of the foreign jurisdiction.”

The practical checklist

Confirm where the data actually resides, get the breach-notification terms in writing, and confirm a real export-and-delete path exists before you sign — not after you need it. Whatever export you’d get on day one has to be able to satisfy how long you have to keep FINTRAC records, which keeps running whether or not you switch platforms. Construction files carry the same underlying logic under a different regulator — see can we put client drawings in a shared model.

Know what your systems can actually prove, before a regulator asks.

A 30-minute call is enough to tell you whether your file storage would hold up under a records request.