Treadstone Associates
Case File · Client Data & Follow-Up

Client data left in a shared spreadsheet

Anonymised, illustrative composite. A master lead spreadsheet was shared with a link setting nobody meant to use — and it sat open for eleven days before anyone noticed, which turned out to matter more than how it happened.

Treadstone Associates · Updated 2026

At a glance

  • • A small team’s master lead spreadsheet held roughly 340 records: names, contact details, mortgage pre-approval ranges, and free-text motivation notes.
  • • An assistant meant to share one filtered tab with a mortgage-broker partner, but changed the sharing setting on the entire master file to “anyone with the link” instead.
  • • The link sat open for 11 days before anyone noticed — the reporting clock under PIPEDA starts running from the day the organization discovers a breach, not the day it happened.
  • • The brokerage had no written policy at all covering sharing settings on cloud files, a gap RECO’s own confidentiality bulletin points at directly.

The situation

A small team — one agent and two licensed assistants — kept a single master spreadsheet of every buyer and seller lead: names, phone numbers, emails, mortgage pre-approval ranges, and free-text notes on each person’s motivation for buying or selling. It was the whole team’s working file, updated daily.

The problem

One assistant, trying to share a filtered view with a mortgage-broker partner for a co-marketing newsletter, changed the sharing setting on the entire master file to “anyone with the link can view” instead of duplicating the relevant tab into a separate file, then pasted that link into a group chat that included people outside the brokerage entirely. The link sat open for eleven days before anyone on the team noticed — a quiet stretch where nobody had reason to check sharing settings on a file everyone used constantly. There was no evidence of actual outside access, but with an “anyone with the link” share, there was also no way to rule it out.

The numbers

Roughly 340 client and lead records were exposed for the eleven-day window: names, phone numbers and emails, mortgage pre-approval ranges, and personal notes on motivation for buying or selling — the kind of financial and personal detail that is sensitive on its own terms, not just in aggregate.

The rule that decided it

PIPEDA requires an organization to report a breach to the Privacy Commissioner where “it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” with notification required “as soon as feasible after the organization determines that the breach has occurred.” That determination clock starts at discovery — day eleven, when the team actually noticed — not at the moment the setting was first changed. Financial pre-approval ranges paired with personal motivation notes reasonably clears the real-risk-of-significant-harm bar on their own, given the potential for targeted, well-informed social engineering against people whose financial position and urgency to sell or buy is already known.

Separately, and regardless of whether that threshold is met, the Act requires an organization to keep a record of every breach of security safeguards for 24 months after the day the organization determines it occurred — not just the ones judged reportable. A brokerage’s own confidentiality duty compounds the gap here: RECO’s Bulletin 2.5 expects a brokerage to have policies on “computer passwords and electronic file storage” controlling who on staff can access and share confidential client information — this team had none.

The outcome

Once discovered, the broker of record ran the real-risk assessment, concluded the exposure of financial pre-approval data and motivation notes plausibly met the significant-harm threshold, reported to the Privacy Commissioner and notified affected clients “as soon as feasible” after discovery, and opened the mandatory 24-month breach record the same week — before any evidence of actual misuse ever surfaced, which is exactly how the real-risk test is designed to work: a possibility standard on the facts as they stood, not proof of harm after the fact.

What it would have cost otherwise

Quietly fixing the sharing setting and saying nothing would have been the deeper failure, not a smaller one. PIPEDA’s own offence provision for knowingly contravening the reporting or record-keeping duties caps at $10,000 on summary conviction or $100,000 on indictment — a penalty aimed squarely at the cover-up, separate from whatever the underlying exposure itself already cost. And the 24-month record obligation is not optional even where the real-risk threshold genuinely is not met: an organization that skips it has failed a separate duty regardless of how the underlying incident is ultimately assessed.

What the 24-month record actually has to contain

The record kept for the full 24 months has to contain enough for the Commissioner to verify compliance with the Act’s reporting and notification duties — not just a note that “a link was fixed.” The team’s file now documents when the setting was changed (as best it could be reconstructed), when it was discovered, what was exposed, who was notified and when, and the reasoning behind the real-risk determination — built once, kept for the full window, rather than assembled after the fact if it were ever asked for.

The tell

If a workflow ever requires someone to remember to duplicate a tab or restrict a share before sending a link out, the failure mode is not “someone forgot” — it is that the convenient default action and the safe action were never the same action. The durable fix is structural: a separate, limited-scope export or view for anything that leaves the master file, so there is no sharing setting on the master file itself that could ever be changed by mistake.

Takeaways

  • • A shared spreadsheet with an over-broad link setting is a breach of security safeguards under PIPEDA in exactly the same way a hack is — the mechanism does not matter, the exposure does.
  • • The reporting clock starts at discovery, not at the moment the exposure began — but a longer undetected window strengthens the case that real harm was possible.
  • • Every breach, reportable or not, needs a 24-month record; only some breaches also need Commissioner and client notification.
  • • A brokerage’s confidentiality duty under RECO’s own rules includes having an actual written policy on file-sharing settings, not just trusting staff to be careful.

Related reading: personal information, defined real and significant harm, defined a related failure, from a different tool

See where AI pays off first in your business.

A 30-minute call is enough to tell you whether AI pays for itself here.