Treadstone Associates
Article · 7 min read

What fields a contact record actually needs

PIPEDA says collect less. FINTRAC says collect these specific things, for these specific clients. A contact record built to satisfy both is not the default CRM template.

Treadstone Associates · Updated 2026

Key takeaways

  • • PIPEDA's limiting-collection principle treats a field with no stated purpose as a liability, not a convenience.
  • • FINTRAC's beneficial-ownership rule requires the name and address of anyone owning or controlling 25%+ of a corporate buyer.
  • • Real estate's FINTRAC business-relationship trigger fires on a single transaction, unlike the two-transaction rule in some other sectors.
  • • Retention periods differ by record type and starting event — FINTRAC's five-year clocks and ITA's six-year clock do not run the same way.

Two federal statutes pull an agent's contact record in opposite directions, and most CRMs are configured as if only one of them existed. PIPEDA says collect less: its “limiting collection” principle, one of the ten fair information principles the Act is built on, means a field with no stated purpose is a liability, not a convenience. FINTRAC, for a subset of your clients, says collect specific things and keep them for years. A contact record built to satisfy both, rather than defaulting to “capture everything,” looks quite different from the sixty-field CRM template most agents inherit and never trim.

The PIPEDA floor: purpose before collection

PIPEDA's principles require you to identify why you are collecting a piece of information before or at the time you collect it, and to limit collection to what that purpose actually needs. Treadstone Law's own explainer on the Act frames the practical test plainly: personal information is “any information about an identifiable individual” — the key question is identifiability, not whether the data feels sensitive. A note in a contact record inferring a client's financial situation from a casual remark, or their marital status from a social media scroll, is personal information you have no articulated purpose for holding — exactly the kind of field the limiting-collection principle exists to discourage.

The FINTRAC ceiling: what a transaction actually requires

For clients you are transacting with, not just marketing to, a second, narrower set of fields is not optional. FINTRAC's client identification guidance requires verifying an individual's identity through one of five accepted methods — government-issued photo ID, a credit-file check, or a dual-process combination, among others — and that verification itself becomes part of the record. For a corporate buyer, the bar is higher again: FINTRAC's beneficial-ownership guidance requires collecting the names and addresses of anyone who “directly or indirectly own or control at least 25% of a corporation or an entity other than a corporation”, plus enough detail to establish the entity's ownership and control structure — fields no marketing-focused CRM template includes by default, and fields you are not permitted to skip once a corporate buyer is in front of you.

A rule most agents do not expect: the relationship itself is a record

Real estate carries an unusual FINTRAC trigger worth knowing specifically. Most sectors — casinos, financial entities — only treat a client as having a formal “business relationship” once a second transaction happens inside a five-year window. Real estate is different: the guidance states the relationship is triggered “the first time that you are required to verify their identity,” meaning a single transaction, not a pattern, starts the clock. Once triggered, you are expected to keep a record of the purpose and intended nature of that relationship — a field most contact records simply do not have, because most CRM templates were not built with a sector-specific trigger like this one in mind.

How long each field actually has to live

The retention period is not uniform, and treating it as one number is a common error. FINTRAC's own recordkeeping guidance is specific: an information record is retained “five years from the day the last business transaction was conducted,” the same clock that governs the business-relationship and beneficial-ownership records. A large-cash-transaction record instead runs from the day the record was created, not from the last transaction — a different starting point for a different record type, inside the same five-year length. On the tax side, entirely separately, ITA section 230(4)(b) requires six years of retention from the end of the relevant taxation year — longer than FINTRAC's clock and running from a different event again. A contact record that only tracks one retention date is quietly wrong about at least one of these obligations.

A worked example: two buyers, two different field sets

A first-time buyer, referred by a past client, who has not yet transacted with you, needs only the marketing-relevant fields: consent type and date, relationship status, source. No FINTRAC obligation has been triggered because you have not yet been required to verify their identity. Once that same buyer's offer is accepted and you move toward closing, the record changes shape: identity verification through one of FINTRAC's accepted methods becomes mandatory, the business-relationship trigger fires on that first required verification, and a record of the relationship's purpose and intended nature needs to exist. If the buyer is purchasing through a numbered corporation rather than personally, the record grows again — director names, and the name and address of anyone holding 25% or more of the company, none of which was relevant a week earlier when they were simply a referred lead. The same person, two different stages, two genuinely different sets of required fields.

A practical field list

Put together, a contact record that actually earns its place holds: identity basics (name, contact details); consent type and start date, for the CASL questions covered elsewhere in tagging a database so you can use it; relationship status — client or self-represented party; and, only for clients you have actually transacted with, the FINTRAC identity-verification record and, where applicable, beneficial-ownership detail for a corporate buyer. What it should not hold, absent a stated purpose, is inferred personal information collected because it was easy to note down at the time, not because any law or transaction required it.

Related: a FINTRAC compliance starter kit, who must be identified under FINTRAC, and whether PIPEDA applies to a solo agent.

Common questions

Does FINTRAC's identity-verification requirement apply to every contact in my database?

No — only to clients you are actually transacting with, where the requirement to verify identity has been triggered. A lead or a past client you are simply marketing to has no FINTRAC identity-verification obligation attached to their record.

What is the beneficial-ownership threshold for a corporate buyer?

25%. FINTRAC's guidance defines a beneficial owner as anyone who directly or indirectly owns or controls at least 25% of the entity, and requires their name and address as part of the record.

Do PIPEDA and FINTRAC ever actually conflict?

Not in practice — they operate on different scopes. PIPEDA's limiting-collection principle constrains what you gather without a stated purpose; FINTRAC supplies the stated purpose for a specific, narrower set of fields once a transaction triggers its requirements. The record you should not be keeping is the one neither law asked for.

Does the FINTRAC business-relationship trigger apply to a lead who never closes?

No. The trigger fires on the first time you are required to verify a client's identity, which happens in connection with an actual transaction, not a marketing relationship. A lead who never reaches that stage never triggers the FINTRAC record-keeping obligations at all.

Build a database that works for you, not against you.

A short call is enough to map your consent status, your tagging structure, and the touch cadence that fits your book.