The material that makes an AI draft useful — a client's name, income, ID details, a property address — is almost always the exact information two Canadian regimes already tell you to protect. The rule is not caution in the abstract; it is written down.
Key takeaways
It is tempting to paste a real client file into an AI tool to save the retyping — a pre-approval letter to summarise, an identification document to extract details from, a client email thread to condense. Two separate Canadian regimes already draw a hard line around exactly this material, for reasons that have nothing to do with AI specifically and everything to do with what real estate professionals are required to protect.
(RECO Bulletin 2.5) states the rule plainly: except as authorized or required by law, brokerages and agents must not disclose any confidential client information to a third party without the client's written consent. An AI vendor — general assistant or niche tool, free or paid — is a third party under this rule the same way a marketing contractor or a photographer would be. Pasting a client's confidential information into a chat window without that consent is a disclosure to a third party, and the bulletin does not carve out an exception for tools that feel like private notepads.
(BCFSA AI Guideline) reinforces the same point from the other direction, specific to AI: never assume the data you input is safeguarded and private. Even anonymised client information can be re-identified when an AI system matches it against other data it has processed, because some platforms store and analyse user interactions to refine their own models. Unless you are certain a tool does not store or use your input, the guideline's instruction is to keep confidential or personal information out of it entirely.
It is a wider category than most agents assume. (BCFSA AI Guideline) defines it as including a person's name, address, phone number, income, and spending habits — and the identification-record duties real estate brokers and developers carry under FINTRAC's rules add date of birth, occupation, and, where funds or accounts are involved, account numbers and every party's involvement in a transaction. (FINTRAC, record keeping guidance) sets out exactly what an information record or a receipt-of-funds record must contain, and reading that list is the fastest way to see how much of a routine file is exactly the material that should never be typed into a public AI tool.
The retention duty runs long after the file closes, and reaches further than just your own client: (FINTRAC, record keeping guidance) requires an information record on any party to the transaction “that is not represented by a real estate broker or sales representatives,” kept “five years from the day the last business transaction was conducted.” Treadstone Law’s overview of FINTRAC obligations for Ontario businesses covers the same reporting-entity framework in plain language, real estate included.
An agent wants a chatbot to turn a buyer's mortgage pre-approval letter into a plain-language summary for a file note. The letter contains the buyer's name, address, income, and the lender's account reference. Pasting the letter directly into a general assistant to get the summary is disclosing all of that to a third party without the written consent (RECO Bulletin 2.5) requires, and it is doing so through a channel (BCFSA AI Guideline) specifically warns may not keep the input private at all. The fix is not to skip the summary — it is to strip the identifying fields before pasting, summarise the structure of the letter generically, and fill the client-specific details back in yourself afterward.
Even where consent exists, the responsibility does not transfer. (PIPEDA, Schedule 1, cl. 4.1.3) is explicit: an organisation is responsible for personal information in its possession, including information transferred to a third party for processing, and must use contractual or other means to keep a comparable level of protection while that third party processes it. A vendor's terms of service promising good data practices are the “contractual means” the clause refers to — they are not a transfer of your own accountability for what happens next.
A short mental test covers most cases without needing to memorise a list: if you would not read the information aloud to a stranger on the phone without your client's permission, do not type it into an AI tool without that same permission. Names, addresses, income, identification numbers and account details all fail that test by default.
Even material a client has consented to sharing can raise a second question once it leaves the country. (OPC, cross-border processing guidelines) confirms PIPEDA does not prohibit transferring personal information abroad for processing, but it does require the transferring organisation to stay accountable for it there, mainly through the contract governing the transfer — and it adds that no contract can override the criminal, national security or other laws of the country the information lands in. A general assistant or niche tool that processes on servers outside Canada is not automatically disqualified by this, but it is one more reason the vendor's own terms need to be read, not assumed, before consented information goes anywhere near it.
A written policy that nobody consults mid-task does not prevent the mistake it describes. What works better is a fixed first step in any AI-assisted task involving a real file: strip identifying fields — name, address, contact details, account or reference numbers — before anything gets pasted, and add them back by hand once the draft is done. That single habit covers the letter of RECO's confidentiality bulletin, BCFSA's caution against assuming privacy, and the FINTRAC categories described above, without requiring a different rule to be remembered for each one.
Related: keeping a record of what AI drafted, writing an AI use policy for yourself and the glossary entry on training data and your listings.
It reduces the risk but does not eliminate the rule. BCFSA's guideline specifically warns that even anonymised information can be re-identified when an AI system matches it against other data sources it has processed, so anonymising is a mitigation, not a substitute for keeping genuinely sensitive fields out entirely.
A property address alone is lower risk than a full client file, but it can still identify a specific transaction or party once combined with other public information, and RECO's advertising rules separately require the owner's consent before advertising anything that could identify a specific property or party to a deal.
No. The confidentiality and accountability rules attach to the disclosure itself, not to whether the tool was chosen by the brokerage. A brokerage-approved tool should have already been vetted for data handling, which is a reason to prefer it, not a reason to skip the underlying consent question.
A short call is enough to map which parts of your week are worth automating first, and which stay yours.