Your client list is personal information under federal law the moment you type a name into it. Here is what PIPEDA actually requires of the database you already have — not the version people assume applies.
Key takeaways
STEP 01 OF 10
PIPEDA applies to organizations that collect, use or disclose personal information "in the course of a commercial activity" — defined as any transaction or regular conduct "that is of a commercial character." A self-employed agent trading real estate is squarely commercial activity by that definition. This is not a rule that only reaches your brokerage; it reaches your own client list, your own phone, and your own laptop directly.
STEP 02 OF 10
Alberta, British Columbia and Quebec have their own private-sector privacy statutes recognized as substantially similar to PIPEDA, and organizations operating wholly within those provinces are generally exempt from PIPEDA for information handled within the province. The practical catch: PIPEDA still governs any handling of that information that crosses a provincial or national border — and most SaaS CRMs host in the US or route data through US infrastructure. That cross-border trigger pulls PIPEDA back into play for an agent physically working in Alberta, BC or Quebec, almost regardless of which provincial law nominally applies.
STEP 03 OF 10
A working privacy policy needs to answer, in plain terms: what's collected, how, and why — explicitly including a purpose like "running a newsletter" — who it's shared with, whether it leaves Canada, how long you keep it, how someone can access or correct it, how they withdraw consent (including unsubscribing), what security measures are in place, and who to contact with a privacy question. No separate double-opt-in requirement for email marketing was found in this research — CASL requires consent, express or implied (step 10), but nothing found here adds a double-opt-in mandate on top of it.
STEP 04 OF 10
Meaningful consent requires four things to be clear: what is collected, with sufficient precision to actually understand it; with whom it's shared; for what purposes; and the risk of harm, including "bodily harm, humiliation, damage to reputation or relationships, loss of employment." Express consent is required when information is sensitive, when the use falls outside reasonable expectations, or where there's meaningful residual risk of harm. There is deliberately "no bright line" for sensitivity — financial, health and similar categories are presumptively sensitive, but context governs the rest.
STEP 05 OF 10
Putting client financial details, motivations or negotiating positions into a third-party AI tool is a disclosure to a party the client likely doesn't reasonably expect, and it's often sensitive on its face — both are independent triggers for express, not implied, consent. This isn't only a PIPEDA question: RECO's own confidentiality duty (step 6) separately bars sharing a client's confidential information — including their motivation for buying or selling, or the amount they'd accept — outside the brokerage without written consent. The two rules point the same direction from different legal bases.
STEP 06 OF 10
Know where personal information actually lives in your practice: your CRM, your email list, your payment processor, your cloud storage. When you share personal information with a third party — a transaction coordinator, a marketing platform, an AI vendor — you remain accountable under PIPEDA for what happens to it; use contracts that bind the vendor to your own privacy standards rather than assuming their terms of service are enough.
STEP 07 OF 10
A staff member who mishandles a client file is a compliance gap, full stop — brief anyone who touches personal information on your actual policies, not a general sense of "be careful with client stuff." This mirrors RECO's own confidentiality duty, which specifically requires brokerages to control which administrative or support staff can access client information through concrete measures like computer passwords and controlled email access.
STEP 08 OF 10
PIPEDA s.10.1(1) requires reporting a breach to the Privacy Commissioner where it's reasonable to believe the breach creates "a real risk of significant harm" — a threshold defined in the Act itself to include bodily harm, humiliation, damage to reputation, financial loss and identity theft. The timing standard is "as soon as feasible after the organization determines that the breach has occurred," not a fixed number of days. Separately, and regardless of whether the RROSH threshold is met, s.10.3 requires recording every breach — reportable or not — and the Breach of Security Safeguards Regulations set that record's retention at exactly 24 months from the day you determine the breach occurred. Knowingly contravening either duty carries a fine of up to $10,000 on summary conviction, or up to $100,000 on indictment, under s.28.
Write the plan down before you need it: who to call, how to assess harm, when to notify affected clients. A plan built at 11pm during an actual incident is a worse plan than one built calmly in advance.
STEP 09 OF 10
Under PIPEDA s.8(3), you must respond to a client's request to see their own file "with due diligence and in any case not later than thirty days" after receiving it. A single 30-day extension is available if meeting the original deadline would unreasonably interfere with your operations, but you must notify the client of the extension, with reasons, within the original 30 days. Silence past the deadline is deemed a refusal under s.8(5) — not a safe default. You may charge a fee only if the client was told the approximate cost in advance and confirmed they wanted to proceed anyway.
STEP 10 OF 10
PIPEDA governs what you may do with a client's data; CASL separately governs whether you can email them commercially. Implied consent under CASL runs 2 years from a purchase or transaction, and 6 months from an inquiry that didn't convert — after that, a name on your list has dropped out of implied consent for commercial electronic messages, even though you may still be entitled to retain the file under PIPEDA. The two clocks measure different things and don't share a calendar.
Assuming Alberta, BC or Quebec agents are exempt from privacy law entirely. They're not exempt — they operate under a different statute, and cross-border data (most CRMs) pulls PIPEDA back in regardless.
Pasting a client's negotiating position into a consumer AI chatbot. That's a disclosure needing express consent under PIPEDA's own sensitivity test, on top of RECO's separate confidentiality duty.
Having no written breach-response plan. The 24-month record requirement applies to every breach, reportable or not — a plan built after the fact is a worse plan, and a missing record is its own separate compliance gap.
Letting a CASL list run past its implied-consent window. A past client's 2-year clock, or a stale lead's 6-month clock, expires quietly — nothing prompts you to notice unless you're tracking it.
Assuming RECO's confidentiality bulletin covers your CRM or AI tool. It explicitly defers CRM, cloud-storage and AI-tool questions to federal privacy law — it does not set its own separate rule for them.
PIPEDA and CASL both hinge on calendar math. Here are two real scenarios, worked through to an actual date.
The breach-record clock. Suppose you determine on March 1, 2027 that a laptop with client files was lost and a breach occurred. Section 6 of the Breach of Security Safeguards Regulations requires the record of that breach to be kept for 24 months from the determination date: March 1, 2027 plus 24 months is March 1, 2029. That date holds regardless of whether the breach itself met the higher RROSH bar for reporting to the Commissioner — the recording duty is separate and unconditional.
The CASL implied-consent clock. A buyer you helped close on June 15, 2025 drops out of your implied-consent window for a marketing email on June 15, 2027 — the 2-year clock under s.10(10)(a). A lead who inquired on January 10, 2026 but never transacted drops out much sooner: January 10, 2026 plus 6 months is July 10, 2026. Two very different dates from two people on the same list, tracked from two different trigger events.
Neither date is a PIPEDA or CASL benchmark for how long you should keep anything — both are the specific legal clocks the two statutes actually run, applied to a real determination date so you can see how fast they move.
PIPEDA itself is federal and doesn't vary by province. The one place province genuinely matters is the carve-out, and Quebec's own regime inside it:
If your practice or your CRM ever crosses into Quebec, its consent bar is the highest of the three carve-out regimes — don't assume Alberta or BC's version is interchangeable with it.
No specific Canadian legal mandate for double opt-in was found in this research. CASL requires consent, express or implied — not specifically a double-confirmation step on top of it.
Yes — PIPEDA and FINTRAC govern safeguards and retention, not the medium. A cloud-only file is fine as long as the safeguards and retention obligations are actually met.
No — Bulletin 2.5 explicitly defers CRM, cloud-storage and AI-tool questions to federal privacy law. It's a fiduciary layer sitting on top of PIPEDA, not a substitute for it.
You have 30 days to respond, with one possible 30-day extension if you notify them within the original window and explain why. Silence past the deadline counts as a refusal, not a safe default.
See also: your first ninety days as a new registrant, express consent, defined, real and significant harm, defined.
A 30-minute call is enough to tell you whether AI pays for itself here.