New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Commerce & industry
Privacy & Security for Real Estate Brokerages
A Canadian brokerage holds exactly what a title fraudster needs: driver's licence and passport copies, receipt-of-funds records and signed agreements of purchase and sale, retained for years because FINTRAC and provincial regulators say so. Privacy Horizon helps brokers of record put workable safeguards around those files, the trust account and an independent-contractor sales force without slowing a single deal. Most engagements start after an impersonation scare, a diverted deposit, a FINTRAC examination notice or a pointed question from the E&O or cyber insurer.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Brokers of record, managing brokers and owners of Canadian brokerages running anywhere from 10 to 500 licensed agents, including franchise offices, where a head-office team of three to thirty supports registrants who work from personal laptops, personal phones and sometimes personal Gmail.
FINTRAC compliance officers and office administrators who double as the de facto privacy contact, staring down the two-year effectiveness review of the AML program with no IT department behind them.
Owners in the middle of an acquisition, a franchise conversion or a move to a new transaction-management or back-office platform, where trust records, ID archives and books of business are about to change hands and someone has to vouch for how they are protected.

Services
Privacy & security services for real estate brokerages
Each service below is scoped for how real estate brokerages actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Real Estate Brokerages
vCISO for real estate brokerages: security leadership across agent devices, MLS access, trust accounts and FINTRAC ID files, without a full-time hire.
Virtual Privacy Officer
Virtual Privacy Officer for Real Estate Brokerages
Virtual Privacy Officer for real estate brokerages: ownership of FINTRAC ID files, TRESA retention, Law 25 duties and client requests, from $2,200/month.
Penetration Testing
Penetration Testing for Real Estate Brokerages
Penetration testing for real estate brokerages: phishing simulations built on offer and deposit lures, website and IDX testing, and paths to trust accounting.
Incident Response Planning
Incident Response Planning for Real Estate Brokerages
Incident response planning for real estate brokerages: rehearsed playbooks for diverted deposits, impersonation attempts, stolen ID files and vendor breaches.
Privacy & Security Policy Development
Privacy & Security Policy Development for Real Estate Brokerages
Privacy policy development for real estate brokerages: FINTRAC collection notices, retention schedules for five and six-year rules, and agent BYOD terms.
Privacy & Security Training
Privacy & Security Training for Real Estate Brokerages
Privacy and security training for real estate brokerages: forged-ID recognition, banking-change fraud drills and document handling, built into FINTRAC training.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Real Estate Brokerages
Vendor security review for real estate brokerages: assess transaction-management, CRM, showing and ID-verification platforms holding client identity documents.
M&A Privacy & Security Due Diligence
M&A Privacy & Security Due Diligence for Real Estate Brokerages
Privacy due diligence for real estate brokerage acquisitions and roll-ups: vet trust records, FINTRAC ID archives and latent compromise before the deal closes.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Real Estate Brokerages
Minimum Viable Privacy for brokerages: a $5,499 CAD/year program reconciling FINTRAC's five-year and TRESA's six-year retention, plus agent training.
What you hold
The records inside a brokerage that criminals actually want
Brokerage data is not generic office paperwork. Several of its record types are direct raw material for fraud, and regulators force you to keep them long after the deal closes.
FINTRAC identification archives
Government ID copies and information records collected to verify buyers and sellers sit on shared drives for the mandatory five years. These are the same documents a homeowner impersonator needs to forge a convincing identity.
Receipt-of-funds and trust records
Bank drafts and Interac e-transfers into the deposit trust account, plus commission trust ledgers in back-office tools like brokerWOLF, map out exactly where money moves and when.
Agreements of purchase and sale
APS files carry financial terms, conditions and closing dates, and often travel with mortgage pre-approvals and buyer financial statements, giving a mailbox intruder everything needed to time a fake payment instruction.
Showing schedules and lockbox data
BrokerBay and ShowingTime bookings and SentriLock or Supra access logs reveal which properties are vacant and when, which turns loose access control into a physical-security problem.
MLS credentials and listing content
Matrix, Stratus and Paragon logins are board-governed and frequently shared between assistants and agents, while listings hold interior photos and tenant details the public feed never shows.
Regulatory map
Five regulators can reach into one brokerage file cabinet
A single residential trade can engage federal AML law, federal privacy law, a provincial regulator's record rules and, in Quebec, Law 25. Each attaches different duties to the same documents.
FINTRAC and the PCMLTFA
Brokers and sales representatives acting for a purchaser or vendor must run a compliance program with a named officer, written policies, a risk assessment, training and a periodic effectiveness review, verify client identity, and keep records such as receipt-of-funds and information records for five years.
October 2025 unrepresented-party rules
Since October 1, 2025, brokerages must also verify identity and keep information records for unrepresented parties in a transaction, and follow new agent and mandatary identification rules, expanding the pool of sensitive documents on file.
PIPEDA for client personal information
As commercial organizations, brokerages owe PIPEDA duties over identity documents, finances and transaction records, including breach reporting to the OPC and affected individuals as soon as feasible where there is a real risk of significant harm, with two-year breach records.
TRESA trade-record retention in Ontario
Under O. Reg. 579/05, RECO expects all trade records to be kept at least six years after the trade completes, and unaccepted offers for one year, so destruction schedules cannot simply mirror the FINTRAC five-year clock.
Quebec Law 25 for agencies
Agencies with Quebec offices need a designated person in charge of personal information, privacy impact assessments for projects such as US-hosted SaaS, and an incident register with notices to the CAI, backed by administrative penalties reaching $10 million or 2% of worldwide turnover.
CASL for farming and marketing
Neighbourhood farming emails, texts to past clients and drip campaigns from CRMs like Follow Up Boss or kvCORE fall under Canada's Anti-Spam Legislation, which governs consent and unsubscribe mechanics.
What goes wrong
How Canadian brokerages get burned
The incident patterns in this industry are specific and well documented, and almost all of them run through either an agent's inbox or the identity-verification step an agent personally performs.
Homeowner impersonation and title fraud
Impersonators with forged ID have listed and sold or mortgaged other people's homes, with at least 32 properties targeted in Ontario and BC, including a Toronto condo sold for $970,000 without its owner's knowledge. RECO reminded registrants in February 2023 that they are required by law to verify the parties in a transaction are who they say.
Deposit and commission diversion
The banking-change play behind major Canadian wire frauds, such as the City of Saskatoon losing over $1 million to a fake CFO request, maps directly onto deposits, balances due on closing and commission payouts.
Agent mailbox compromise
A phished Microsoft 365 or Gmail account lets an attacker quietly monitor live deals, learn the players and the dates, then send perfectly timed fraudulent payment instructions from a trusted thread.
Theft of FINTRAC ID files
Ransomware on the office server or one lost agent laptop can expose five years of driver's licences and passports, handing impersonators the raw material for the fraud regulators keep warning about.
Vacant-property intelligence
Showing systems and lockbox codes disclose when homes sit empty. Weak control over that access has consequences no firewall addresses, from squatting to staged viewings by fraudsters.
When organisations call us
The moments brokerages call us
Security and privacy work in this industry is bought in the quiet months, usually November through January, and almost always because one of these events forced the issue.
A FINTRAC examination or effectiveness review
An examination letter, or the scheduled two-year review of the AML compliance program, surfaces gaps in how identity records are stored, accessed and destroyed.
An impersonation attempt or diverted funds
An agent catches a forged licence at a listing appointment, or a buyer reports their deposit went to the wrong account, and the broker of record wants a defensible response before it happens again.
The October 1, 2025 rule change
New identification and record duties for unrepresented parties mean more ID collection by more agents, and brokerages need collection, storage and retention practices that keep pace.
Insurance renewal or a new platform
Cyber and E&O renewals now probe MFA and payment controls, and migrations to new transaction-management or back-office systems raise questions nobody in-house can answer.
A roll-up, merger or franchise conversion
When books of business, trust records and ID archives change hands, buyers and franchisors increasingly expect privacy and security diligence before signatures.
Real Estate Brokerages: privacy & security questions, answered
Yes. The brokerage is the commercial organization collecting client personal information through its registrants, and the contractor status of agents does not shift accountability away from it. That is precisely what makes this niche hard: the entity with the legal duties does not manage the endpoints, inboxes or habits of the people doing the collecting, so safeguards have to be designed for an independent workforce rather than imposed like an employee policy.
Three things stack up. Federal AML law forces you to collect and keep government ID and funds records for five years, so the fraud-ready documents are guaranteed to be there. Money moves in large, predictable amounts through deposits, closings and commissions, so one convincing email can redirect six figures. And the workforce is hundreds of contractors on personal devices, so the attack surface is wide and largely outside head-office control.
Depending on the facts and provinces involved: the OPC under PIPEDA, Alberta's OIPC under its PIPA, the CAI under Quebec Law 25, plus FINTRAC where AML records or reporting are implicated, and your provincial real estate regulator, whether RECO, BCFSA, RECA or the OACIQ. Your bank, your insurer and possibly a board operating the MLS may also need calls. Sorting out who hears what, and when, is a core reason brokerages formalize their response plans.
The spring market from roughly February to June consumes every agent and admin, so meaningful projects rarely land then. Brokerages that get this done book assessments, policy work and training between November and January, when sales meetings have room on the agenda and administrators can pull records without a closing deadline looming.
Yes, contractually. Access to board systems such as TRREB's is governed by agreements, and boards police unauthorized access and data-sharing. Shared Matrix, Stratus or Paragon logins are therefore both a security weakness and a potential breach of board terms, which is why credential hygiene for MLS access shows up in nearly every brokerage engagement we run.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What should I do after a data breach?
- What is multi-factor authentication, and do I need it?
- How can I protect my personal and business information from cyberattacks?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.