Anonymised, illustrative composite. A master lead spreadsheet was shared with a link setting nobody meant to use — and it sat open for eleven days before anyone noticed, which turned out to matter more than how it happened.
At a glance
A small team — one agent and two licensed assistants — kept a single master spreadsheet of every buyer and seller lead: names, phone numbers, emails, mortgage pre-approval ranges, and free-text notes on each person’s motivation for buying or selling. It was the whole team’s working file, updated daily.
One assistant, trying to share a filtered view with a mortgage-broker partner for a co-marketing newsletter, changed the sharing setting on the entire master file to “anyone with the link can view” instead of duplicating the relevant tab into a separate file, then pasted that link into a group chat that included people outside the brokerage entirely. The link sat open for eleven days before anyone on the team noticed — a quiet stretch where nobody had reason to check sharing settings on a file everyone used constantly. There was no evidence of actual outside access, but with an “anyone with the link” share, there was also no way to rule it out.
Roughly 340 client and lead records were exposed for the eleven-day window: names, phone numbers and emails, mortgage pre-approval ranges, and personal notes on motivation for buying or selling — the kind of financial and personal detail that is sensitive on its own terms, not just in aggregate.
PIPEDA requires an organization to report a breach to the Privacy Commissioner where “it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” with notification required “as soon as feasible after the organization determines that the breach has occurred.” That determination clock starts at discovery — day eleven, when the team actually noticed — not at the moment the setting was first changed. Financial pre-approval ranges paired with personal motivation notes reasonably clears the real-risk-of-significant-harm bar on their own, given the potential for targeted, well-informed social engineering against people whose financial position and urgency to sell or buy is already known.
Separately, and regardless of whether that threshold is met, the Act requires an organization to keep a record of every breach of security safeguards for 24 months after the day the organization determines it occurred — not just the ones judged reportable. A brokerage’s own confidentiality duty compounds the gap here: RECO’s Bulletin 2.5 expects a brokerage to have policies on “computer passwords and electronic file storage” controlling who on staff can access and share confidential client information — this team had none.
Once discovered, the broker of record ran the real-risk assessment, concluded the exposure of financial pre-approval data and motivation notes plausibly met the significant-harm threshold, reported to the Privacy Commissioner and notified affected clients “as soon as feasible” after discovery, and opened the mandatory 24-month breach record the same week — before any evidence of actual misuse ever surfaced, which is exactly how the real-risk test is designed to work: a possibility standard on the facts as they stood, not proof of harm after the fact.
Quietly fixing the sharing setting and saying nothing would have been the deeper failure, not a smaller one. PIPEDA’s own offence provision for knowingly contravening the reporting or record-keeping duties caps at $10,000 on summary conviction or $100,000 on indictment — a penalty aimed squarely at the cover-up, separate from whatever the underlying exposure itself already cost. And the 24-month record obligation is not optional even where the real-risk threshold genuinely is not met: an organization that skips it has failed a separate duty regardless of how the underlying incident is ultimately assessed.
The record kept for the full 24 months has to contain enough for the Commissioner to verify compliance with the Act’s reporting and notification duties — not just a note that “a link was fixed.” The team’s file now documents when the setting was changed (as best it could be reconstructed), when it was discovered, what was exposed, who was notified and when, and the reasoning behind the real-risk determination — built once, kept for the full window, rather than assembled after the fact if it were ever asked for.
If a workflow ever requires someone to remember to duplicate a tab or restrict a share before sending a link out, the failure mode is not “someone forgot” — it is that the convenient default action and the safe action were never the same action. The durable fix is structural: a separate, limited-scope export or view for anything that leaves the master file, so there is no sharing setting on the master file itself that could ever be changed by mistake.
Related reading: personal information, defined real and significant harm, defined a related failure, from a different tool
A 30-minute call is enough to tell you whether AI pays for itself here.