MVP program · Commerce & industry
Minimum Viable Privacy Program for Real Estate Brokerages
Minimum Viable Privacy gives a small or mid-sized brokerage the essential privacy foundation it needs without hiring a compliance officer or committing to an ongoing Virtual Privacy Office retainer: a client privacy notice, a retention schedule that reconciles FINTRAC's five years with TRESA's six, a breach checklist and agent training, delivered as a fixed program for $5,499 CAD a year. It suits the brokerage that has never formally assigned privacy duties but now faces a FINTRAC examination, an impersonation scare, or a broker of record who wants something written down before the next E&O renewal.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the minimum program has to cover for an independent brokerage
A 15-to-40-agent brokerage does not need a full privacy department, but it does need working answers to the questions FINTRAC, TRESA and its own agents raise every month.
Where FINTRAC's five years meets TRESA's six
FINTRAC's five-year minimum on identification and receipt-of-funds records and Ontario's six-year TRESA retention on trade records apply to overlapping documents, and the program sets one schedule that satisfies both instead of guessing which clock governs which folder.
What agents may keep on personal devices
A workable rule for the licence and passport copies, signed forms and text threads that live on an independent contractor's own phone and laptop, written for people you cannot manage like employees.
A client privacy notice a small office actually needs
One page covering FINTRAC ID collection, deposit handling and marketing consent, worded for a 20-agent independent rather than adapted from a franchise head-office document describing systems you do not run.
A response the office can follow when a deposit goes missing
A short checklist for the administrator: what to say to the buyer, who to call first between the bank, the brokerage's insurer and FINTRAC, and what not to do while the wire is traced.
Deletion requests inside a mandatory retention period
A written position on what happens when a client asks for their file gone before FINTRAC's or TRESA's clock has run, so the administrator has an answer ready instead of improvising one under pressure.
Regulatory map
Which rules an independent brokerage's program has to satisfy
An independent brokerage answers to the same federal AML law and provincial trade rules as a 300-agent franchise, just with far less staff time to work through them.
FINTRAC's core obligations under the PCMLTFA
A brokerage acting for a buyer or seller must verify client identity and keep information and receipt-of-funds records for five years, obligations that apply from the first licensed transaction regardless of office size.
Ontario's TRESA retention rule under O. Reg. 579/05
Trade records must be kept at least six years after completion and unaccepted offers for one year, a schedule the program reconciles with FINTRAC's shorter clock rather than leaving to guesswork.
PIPEDA accountability for a contractor-run office
The brokerage, not the individual agent, is the commercial organization accountable for client personal information under PIPEDA, with breach-reporting duties to the OPC and affected clients where there is real risk of significant harm.
A Law 25 person in charge for Quebec offices
Any Quebec presence needs a named person in charge of personal information and a basic process for CAI incident notification, sized to a small office rather than a head-office compliance team.
What goes wrong
What the minimum brokerage program is built to prevent
Independent brokerages are not breached by exotic attacks. They are caught out by the same ordinary gaps regulators and fraudsters both know to look for.
An ID archive an impersonator would love to find
Years of driver's licence and passport copies on a shared drive with no destruction date are exactly the raw material behind the title-fraud pattern RECO has warned registrants about since 2023.
A retention schedule that doesn't exist on paper
Without a written schedule, an office either destroys FINTRAC records too early or keeps TRESA files decades past any defensible purpose, and both are indefensible to an examiner in different ways.
A commission payout approved by email alone
The same supplier-impersonation pattern behind major Canadian wire frauds targets deposit and commission instructions here, and a program without basic training leaves the office administrator as the only line of defence.
A deletion request with no documented answer
A client demanding their file gone before the retention period ends, with no policy to point to, forces the administrator to improvise a legal answer in the middle of an unrelated phone call.
Our mvp program for real estate brokerages
What the fixed MVP engagement delivers for an office
The program follows the same fixed structure as any MVP engagement, sized here to a brokerage with agents rather than employees and two competing retention clocks.

A baseline review scoped to ID intake and trust records
A review of current practice against FINTRAC, TRESA, PIPEDA and, where relevant, Law 25, covering ID intake, trust-account communications and the CRM in a single pass sized to your office.
Priorities set by what a small brokerage risks first
Direction on what matters first for a brokerage your size, typically the retention schedule, the client notice and deposit-fraud awareness, rather than a generic list built for a head office you do not have.
Safeguards sized to an office of agents, not employees
Practical guidance on safeguards an independent office can actually run, from shared-drive access rules to how MLS credentials get issued and revoked, without assuming a dedicated IT function.
A structure built to extend to a new office or headcount
The foundation is built to extend cleanly if you add a Quebec office, grow past twenty-five agents, or later move to an ongoing Virtual Privacy Office retainer.
Twelve hours built around your November-to-January window
The engagement includes twelve hours of coaching, core policy drafting, readiness-assessment workshops and training with ten included seats, enough to cover the broker of record, the administrator and a rotating group of agents.
How the engagement runs
How the twelve-hour engagement runs at a brokerage
MVP is a fixed, one-time build, timed to the quiet months when agents and admin staff actually have room on the calendar.
Step 1
Baseline review of ID intake and retention
We look at how identification is collected and stored, what the current retention practice actually is, and where FINTRAC and TRESA timelines are being conflated or ignored.
Step 2
Build the priority controls for your office
Coaching hours go first toward the retention schedule, the client notice and a deposit-fraud response checklist, since these are what an examiner, an insurer or a client is most likely to test.
Step 3
Run the agent readiness workshops
Short workshops walk the broker of record and administrator through the new procedures, and the included training seats cover agents on forged-ID recognition and banking-change red flags.
Step 4
Hand over a program the office can maintain
You leave with written policies, one reconciled retention schedule and a breach checklist your administrator can run independently, plus a clear sense of when the office would outgrow it.
What it costs
What Minimum Viable Privacy costs for a brokerage
Minimum Viable Privacy is priced at $5,499 CAD per year on a twelve-month term, and includes twelve hours of coaching, policy development, readiness-assessment workshops and training for ten seats, the fixed package described on our pricing page.
For most independent brokerages this single program covers the reconciled retention schedule, the client notice, deposit-fraud training and a breach checklist in one pass. A franchise network with multiple offices, or a brokerage that outgrows the ten included training seats, is usually better served by the Virtual Privacy Office retainer instead.
Real Estate Brokerages: MVP program questions, answered
A client privacy notice covering FINTRAC ID collection and deposit handling; one retention schedule that reconciles the five-year FINTRAC clock with TRESA's six years; a short response checklist for a diverted deposit or an impersonation attempt; documented CASL consent for your farming lists; and basic agent training on forged ID and banking-change fraud. That is exactly what the MVP engagement builds, sized to an office with no dedicated compliance staff.
You explain, in writing, that FINTRAC and TRESA require the brokerage to retain specific records for a set period regardless of the client's wishes, and that deletion before those clocks run would put the brokerage offside with its own regulators. What can usually be reduced is marketing use and internal access to the file, even while the retention copy stays in place. MVP gives your administrator a written position and a template response so this conversation is not improvised every time it comes up.
Yes, because the two roles cover different ground. Your compliance officer runs the AML program: verification, reporting and the effectiveness review. MVP builds the privacy side sitting next to it, the client notice, the reconciled retention schedule and PIPEDA's access and breach duties, which FINTRAC's rules do not address and which your compliance officer usually has no mandate or time to build.
Yes, the program includes training seats, ten of them, that can be applied to agents as well as head-office staff, focused on forged-ID recognition, deposit and commission fraud red flags, and safe handling of client documents. Since agents are the ones actually collecting ID and fielding banking-change requests in the field, most brokerages point the majority of their seats at the sales force rather than the administrator alone.
It should, and that is how we schedule it. The coaching hours and workshops run in the quieter months, November through January, when sales meetings have room on the agenda and administrators can pull records without a closing deadline looming. Starting in the spring market against agents' calendars is possible but slower, since the busiest months of the year leave little room for a new procedure to land.
The written policies, retention schedule and response checklist stay yours to run. Many brokerages renew the annual term as agent counts, platforms and rules change, particularly after the October 2025 FINTRAC updates on unrepresented parties, and some move into an ongoing Virtual Privacy Office retainer once growth or a Quebec office adds enough ongoing questions to justify it.
More for real estate brokerages
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.