Secure information handling Current

Storing client identity evidence securely in Canada

Two obligations sit on top of each other here: keep it retrievable, and keep it protected.

Client identity evidence has to stay both quickly retrievable if FINTRAC asks for it, and properly protected under PIPEDA's safeguards principle. This guide sets out what both of those mean in practice. It is general information, not a substitute for your firm's own security policy or advice.

Action plan

1 Keep records in a form you can produce within 30 days FINTRAC's own timeframe for producing records on request should shape how you store them.

FINTRAC's record-keeping guidance for accountants states that records must be kept in such a manner that they can be provided to FINTRAC within 30 days of a request, and that records may be kept electronically as long as a paper copy can be readily produced. Store identity evidence in a way that meets that timeframe, rather than in a form that would need to be reconstructed from scattered files if it were ever requested.

  • Store identity evidence so it can be produced within 30 days of a request
  • If stored electronically, confirm a paper copy can be readily produced from it
  • Avoid storing identity evidence only in scattered, unindexed correspondence

Done when: Stored identity evidence can be produced within 30 days, in electronic or paper form

FINTRAC: record keeping requirements for accountants
2 Apply safeguards proportionate to the sensitivity of the information PIPEDA's safeguards principle scales protection to how sensitive the information is, not a single fixed standard.

The Office of the Privacy Commissioner of Canada's guidance on PIPEDA's safeguards principle describes protecting personal information against loss, theft, and unauthorized access, disclosure, copying, use, or modification, with security appropriate to the sensitivity of the information. It describes physical measures such as locked storage and restricted premises, technological measures such as passwords and encryption, and organizational measures such as limiting who can access the information and staff training.

  • Apply a level of protection that matches how sensitive the identity evidence is
  • Combine physical, technological, and organizational safeguards rather than relying on just one
  • Limit who inside the firm can access stored identity evidence

Done when: Stored identity evidence has physical, technological, and organizational safeguards proportionate to its sensitivity

OPC Canada: PIPEDA safeguards principle
3 Dispose of identity evidence with the same care you stored it Disposal is part of safeguarding, not a separate afterthought once retention ends.

OPC guidance on the safeguards principle notes that care must be used in the disposal or destruction of personal information, to prevent unauthorized parties from gaining access to it. Follow your firm's own retention and disposal policy once identity evidence is no longer required to be kept, rather than leaving it in ordinary storage indefinitely.

  • Follow your firm's retention and disposal policy once identity evidence is no longer required
  • Dispose of physical and electronic copies in a way that prevents unauthorized recovery
  • See the separate guide on setting a record retention schedule

Done when: Identity evidence no longer required to be kept is disposed of in line with your firm's retention and disposal policy

See setting a record retention schedule