PIPEDA says collect less. FINTRAC says collect these specific things, for these specific clients. A contact record built to satisfy both is not the default CRM template.
Key takeaways
Two federal statutes pull an agent's contact record in opposite directions, and most CRMs are configured as if only one of them existed. PIPEDA says collect less: its “limiting collection” principle, one of the ten fair information principles the Act is built on, means a field with no stated purpose is a liability, not a convenience. FINTRAC, for a subset of your clients, says collect specific things and keep them for years. A contact record built to satisfy both, rather than defaulting to “capture everything,” looks quite different from the sixty-field CRM template most agents inherit and never trim.
PIPEDA's principles require you to identify why you are collecting a piece of information before or at the time you collect it, and to limit collection to what that purpose actually needs. Treadstone Law's own explainer on the Act frames the practical test plainly: personal information is “any information about an identifiable individual” — the key question is identifiability, not whether the data feels sensitive. A note in a contact record inferring a client's financial situation from a casual remark, or their marital status from a social media scroll, is personal information you have no articulated purpose for holding — exactly the kind of field the limiting-collection principle exists to discourage.
For clients you are transacting with, not just marketing to, a second, narrower set of fields is not optional. FINTRAC's client identification guidance requires verifying an individual's identity through one of five accepted methods — government-issued photo ID, a credit-file check, or a dual-process combination, among others — and that verification itself becomes part of the record. For a corporate buyer, the bar is higher again: FINTRAC's beneficial-ownership guidance requires collecting the names and addresses of anyone who “directly or indirectly own or control at least 25% of a corporation or an entity other than a corporation”, plus enough detail to establish the entity's ownership and control structure — fields no marketing-focused CRM template includes by default, and fields you are not permitted to skip once a corporate buyer is in front of you.
Real estate carries an unusual FINTRAC trigger worth knowing specifically. Most sectors — casinos, financial entities — only treat a client as having a formal “business relationship” once a second transaction happens inside a five-year window. Real estate is different: the guidance states the relationship is triggered “the first time that you are required to verify their identity,” meaning a single transaction, not a pattern, starts the clock. Once triggered, you are expected to keep a record of the purpose and intended nature of that relationship — a field most contact records simply do not have, because most CRM templates were not built with a sector-specific trigger like this one in mind.
The retention period is not uniform, and treating it as one number is a common error. FINTRAC's own recordkeeping guidance is specific: an information record is retained “five years from the day the last business transaction was conducted,” the same clock that governs the business-relationship and beneficial-ownership records. A large-cash-transaction record instead runs from the day the record was created, not from the last transaction — a different starting point for a different record type, inside the same five-year length. On the tax side, entirely separately, ITA section 230(4)(b) requires six years of retention from the end of the relevant taxation year — longer than FINTRAC's clock and running from a different event again. A contact record that only tracks one retention date is quietly wrong about at least one of these obligations.
A first-time buyer, referred by a past client, who has not yet transacted with you, needs only the marketing-relevant fields: consent type and date, relationship status, source. No FINTRAC obligation has been triggered because you have not yet been required to verify their identity. Once that same buyer's offer is accepted and you move toward closing, the record changes shape: identity verification through one of FINTRAC's accepted methods becomes mandatory, the business-relationship trigger fires on that first required verification, and a record of the relationship's purpose and intended nature needs to exist. If the buyer is purchasing through a numbered corporation rather than personally, the record grows again — director names, and the name and address of anyone holding 25% or more of the company, none of which was relevant a week earlier when they were simply a referred lead. The same person, two different stages, two genuinely different sets of required fields.
Put together, a contact record that actually earns its place holds: identity basics (name, contact details); consent type and start date, for the CASL questions covered elsewhere in tagging a database so you can use it; relationship status — client or self-represented party; and, only for clients you have actually transacted with, the FINTRAC identity-verification record and, where applicable, beneficial-ownership detail for a corporate buyer. What it should not hold, absent a stated purpose, is inferred personal information collected because it was easy to note down at the time, not because any law or transaction required it.
Related: a FINTRAC compliance starter kit, who must be identified under FINTRAC, and whether PIPEDA applies to a solo agent.
No — only to clients you are actually transacting with, where the requirement to verify identity has been triggered. A lead or a past client you are simply marketing to has no FINTRAC identity-verification obligation attached to their record.
25%. FINTRAC's guidance defines a beneficial owner as anyone who directly or indirectly owns or controls at least 25% of the entity, and requires their name and address as part of the record.
Not in practice — they operate on different scopes. PIPEDA's limiting-collection principle constrains what you gather without a stated purpose; FINTRAC supplies the stated purpose for a specific, narrower set of fields once a transaction triggers its requirements. The record you should not be keeping is the one neither law asked for.
No. The trigger fires on the first time you are required to verify a client's identity, which happens in connection with an actual transaction, not a marketing relationship. A lead who never reaches that stage never triggers the FINTRAC record-keeping obligations at all.
A short call is enough to map your consent status, your tagging structure, and the touch cadence that fits your book.