Going paperless does not simplify your retention obligations — it just means the record now lives somewhere you have to be able to produce it from. Two federal regimes govern what a digital-only real estate practice actually has to keep, and they run on different clocks for different reasons.
Key takeaways
FINTRAC’s own definition is broader than agents sometimes assume: a real estate broker or sales representative is anyone “authorized under provincial legislation to act as an agent for purchasers or vendors in respect of a purchase or sale of real property,” and the obligation applies “even if you do not receive commission for the real estate transaction and regardless of whether you have related fiduciary duties with respect to the transaction.” (FINTRAC, Real estate brokers and sales representatives) Two carve-outs are worth knowing precisely: pure property-management activity — leases and rental management, as opposed to purchases or sales — falls outside these obligations entirely, and where a sales representative acts on behalf of a broker, most of the requirements below are the broker’s responsibility, with the reader-facing exception of suspicious-transaction reporting, which stays with the individual.
Every real estate broker or sales representative acting on a purchase or sale is a reporting entity under FINTRAC’s guidance, and the retention duty attaches to several distinct record types, each running from a different trigger. (FINTRAC, Recordkeeping — real estate) A Suspicious Transaction Report copy must be kept at least five years from the day it was submitted; a Large Cash Transaction Report copy, at least five years from the date it was created; an information record and a business-relationship record, five years from the day of the last business transaction conducted with that client. The practical consequence is that “five years” is not one clock across your file — a client relationship that stays active resets the information-record clock with each new transaction, while a filed report’s clock starts the day it was filed and does not move again. receipt of funds record defined and the FINTRAC compliance starter kit cover the individual record types and how to actually set this up in practice.
This is also the correct answer to a question agents often direct at RECO instead: RECO itself does not publish a separate deal-file retention period. FINTRAC’s five-year rule is the retention duty that actually governs a real estate transaction file, and the tax-side retention obligation under the Income Tax Act runs separately again. Treating “keep the file five years” as a RECO rule rather than a FINTRAC one is a common, and mostly harmless, mislabelling — but it matters if you are ever asked which regulator is actually enforcing the retention duty, because the answer determines who you are answerable to if a record cannot be produced.
PIPEDA layers a second obligation on top, and it is not about the transaction file — it is about your own security incidents. Section 10.3(1) of the Act states an organization “shall, in accordance with any prescribed requirements, keep and maintain a record of every breach of security safeguards involving personal information under its control.” (PIPEDA, s.10.3) Read that duty carefully: it applies to every breach, independent of whether the separate reporting threshold in section 10.1 — a real risk of significant harm — was ever met. A breach too minor to report to the Privacy Commissioner still has to be logged. The prescribed record-keeping period, set by regulation, is 24 months from the day the organization determines the breach occurred, and the record must contain enough information for the Commissioner to verify compliance with the reporting and notification duties. (Breach of Security Safeguards Regulations, s.6) what counts as a reportable breach walks through the reporting threshold itself in more depth.
The reporting trigger itself is worth having precisely, because “significant harm” is not left to guesswork — the Act defines it: “bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property.” Both the report to the Commissioner and the notification to affected individuals are required “as soon as feasible after the organization determines that the breach has occurred” — there is no fixed number of days, but the standard is immediacy from the point of determination, not from whenever it becomes convenient to act.
Neither FINTRAC’s retention rule nor PIPEDA’s breach-record duty is about the medium a record is kept in — both are about whether the record exists, is retrievable, and is adequately safeguarded for its retention period. A cloud-only file satisfies both regimes exactly the way a filing cabinet does, provided it can actually produce what FINTRAC or the Commissioner would ask for, within the correct retention window described above. Where digital-only practice actually adds risk is on the safeguards side, not the retention side: a vendor holding your client data is a party PIPEDA still holds you accountable for, and a SaaS agreement that is vague about data ownership, export rights, or deletion on termination leaves you exposed to exactly the kind of incident section 10.3’s 24-month logging duty would then apply to. privacy practices for your database covers what a vendor agreement should actually say before you sign it, which is a cheaper fix than a well-run breach-logging process after the fact.
A brokerage’s cloud CRM vendor discloses that a configuration error exposed a subset of client contact information for several days before being caught and fixed. No evidence emerges that the data was actually accessed by anyone outside the vendor. Two separate duties apply here, not one. First, an assessment of whether this creates a real risk of significant harm under the definition above — if it does not, on a documented assessment, no report to the Commissioner and no individual notification is required under section 10.1. Second, and independent of that conclusion, section 10.3’s logging duty still applies regardless: the incident has to be recorded, and the record kept for 24 months from the date the breach was determined to have occurred, precisely because the reporting threshold and the logging duty are not the same test. Treating “we decided not to report it” as the end of the obligation is the mistake this rule is specifically built to catch.
Not always — it depends on the record type. A filed report’s copy is kept from its submission or creation date, while an information record or business-relationship record runs five years from the last business transaction conducted with that client, which can be later than closing if the relationship continues.
Yes. PIPEDA’s s.10.3 record-keeping duty applies to every breach of security safeguards, independent of whether it met the separate real-risk-of-significant-harm threshold that triggers a report to the Commissioner under s.10.1.
No confirmed RECO-published retention period exists for the deal file itself — FINTRAC’s five-year rule is the retention duty that actually governs a real estate transaction file, separate again from the Income Tax Act’s own retention rule.
A short call can map your current file and CRM setup against FINTRAC and PIPEDA’s specific retention windows.