FINTRAC and AML Compliance for Canadian Businesses: Privacy and Reporting Obligations
FINTRAC reporting and privacy together: verifying client identity, reporting suspicious transactions, and retaining records without breaching PIPEDA.
Anti-money laundering (AML) and counter-terrorist financing (CTF) obligations under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act create unique privacy tensions. Businesses subject to FINTRAC reporting must collect more personal information than they might otherwise — including identity verification details, third-party and beneficial ownership information, and enhanced due diligence for certain clients — while simultaneously meeting PIPEDA's limiting collection principle. Here's how these obligations interact.
Last updated: April 2026
Who Is Subject to FINTRAC Reporting?
The Proceeds of Crime (Money Laundering) and Terrorist Financing Act applies to "reporting entities" — a broad category including:
- Financial institutions: Banks, credit unions, caisses populaires, loan companies, trust companies
- Securities dealers: Investment dealers, portfolio managers, securities advisors
- Life insurance companies and agents/brokers
- Accountants and accounting firms (for specific activities)
- Real estate brokers and sales representatives (for real estate transactions)
- Mortgage brokers and administrators
- Money services businesses (MSBs): Currency exchange, money transfer services, virtual currency businesses
- British Columbia notaries
- Casinos
- Dealers in precious metals and precious stones
The full current list is on FINTRAC's Who must report to FINTRAC page. If your business falls into any of these categories, FINTRAC reporting obligations apply — and they interact significantly with your PIPEDA obligations.
What FINTRAC Requires You to Collect
Client Identification (Know Your Customer — KYC)
When opening accounts or conducting certain transactions, reporting entities must verify client identity:
For individuals:
- Full legal name
- Date of birth
- Address
- Identity verified using a method permitted by FINTRAC — for example, authentic, valid and current government-issued photo identification (not municipal), the credit file method, or the dual-process method (FINTRAC: Methods to verify identity)
For corporations and entities:
- Corporate name, address, nature of business
- Names of all directors
- Ownership and control structure
Third-Party Determination
When conducting transactions on behalf of a third party, you must identify the third party (name, address, relationship to client, nature of business).
Beneficial Ownership
For corporate clients, you must obtain the names and addresses of all persons who own or control, directly or indirectly, 25% or more of the shares (PCMLTF Regulations, s. 138).
Politically Exposed Persons (PEPs) and Heads of International Organizations (HIOs)
For account holders determined to be politically exposed foreign persons (or their family members or close associates), financial entities, securities dealers and casinos must take reasonable measures to establish the source of funds and the source of the person's wealth and obtain senior management approval to keep the account open. For domestic PEPs, HIOs and their family members or close associates, these measures apply where the entity considers there is a high risk (PCMLTF Regulations, s. 121).
Transaction Records
Specific transactions must be recorded and/or reported — for example, receipt of $10,000 or more in cash in a single transaction, international electronic funds transfers of $10,000 or more, and receipt of $10,000 or more in virtual currency (PCMLTF Regulations).
How FINTRAC Obligations Interact With PIPEDA
The Conflict: Collection Limitation vs. Compliance Obligations
PIPEDA Principle 4 (Limiting Collection) says collect only what's necessary for your purpose. FINTRAC requires collecting specific personal information regardless of whether your business would otherwise want it.
The resolution: PIPEDA permits collection without knowledge or consent for the purpose of making a disclosure that is required by law (s. 7(1)(e)(ii)), and permits disclosure without consent to FINTRAC as required by section 7 of the PCMLTFA (s. 7(3)(c.2)) and where otherwise required by law (s. 7(3)(i)). Information required by the PCMLTFA and its regulations is information your business needs for a legally required purpose.
In practice: You must tell clients you're collecting their identification information for AML/KYC purposes — but you don't need their consent to collect what FINTRAC requires.
Privacy Notice for AML/KYC Collection
Your privacy policy should disclose FINTRAC-related collection:
"We are required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act to verify the identity of our clients, record certain transactions, and report certain activities to FINTRAC (Financial Transactions and Reports Analysis Centre of Canada). Information collected for these purposes is used for legal compliance and may be reported to FINTRAC as required by law."
Suspicious Transaction Reports (STRs)
Reporting entities must file STRs with FINTRAC when there are reasonable grounds to suspect a transaction involves proceeds of crime or terrorist financing. STR filing involves disclosing client personal information to FINTRAC without the client's knowledge or consent — this is expressly authorized by PIPEDA s. 7(3)(c.2).
Tipping off prohibition: No person or entity may disclose that they have made, are making or will make an STR, or disclose its contents, with the intent to prejudice a criminal investigation (PCMLTFA s. 8).
When a client requests access to their file: If the request would reveal a disclosure made to FINTRAC under s. 7(3)(c.2), or the existence of information relating to it, PIPEDA s. 9(2.1)–(2.4) requires you to notify FINTRAC in writing and without delay and not respond before FINTRAC replies (within 30 days); if FINTRAC objects, you must refuse that part of the request and notify the Privacy Commissioner. Document these steps.
Retention of KYC Records
The PCMLTF Regulations (s. 148) require records to be kept for at least five years — measured from the day the account is closed for account records, from the last business transaction for client information and entity-existence records, or otherwise from the day the record was created. This creates a retention floor — you must retain these records for that period even if PIPEDA alone might allow earlier deletion.
Disclosure to Law Enforcement
FINTRAC compiles financial intelligence and discloses to law enforcement and national security agencies. As a reporting entity feeding FINTRAC, your clients' transaction data may ultimately reach law enforcement through this channel. Disclose this possibility in your privacy policy.
Building an AML/Privacy Compliance Framework
Separate Your AML Records
Maintain AML/KYC records separately from general client files. This enables:
- Clear access control (only compliance-authorized staff access KYC records)
- Easier management of FINTRAC's specific retention period
- Clean responses to access requests (you can clearly identify which records are FINTRAC-mandated vs. generally collected)
Access Request Responses for AML Records
When a client makes a PIPEDA access request:
- Provide non-AML personal information in the normal course
- For KYC records: Provide identification information collected (the client's own ID information)
- For anything relating to an STR or other disclosure to FINTRAC: follow the PIPEDA s. 9(2.1)–(2.4) notification process described above
Staff Training for AML/Privacy
Staff handling AML obligations need training on:
- What KYC information must be collected and why
- How to explain AML obligations to clients (without revealing STR details)
- The tipping-off prohibition
- How to respond when clients ask why you need certain information
Practical Compliance Checklist
For all FINTRAC-regulated businesses:
- Update privacy policy to disclose FINTRAC collection obligations
- Create client identification record system with retention of at least five years (PCMLTF Regulations s. 148)
- Train compliance staff on AML/privacy interaction
- Document your STR process (including information withholding on access requests)
- Review beneficial ownership identification and record-keeping
- Conduct regular AML compliance programme review (FINTRAC requires documented compliance programme)
Frequently Asked Questions
Q: Can we use FINTRAC-collected information for marketing? A: No — information collected under legal compulsion (FINTRAC) must be used only for that legal purpose. Using KYC information for marketing would violate PIPEDA Principle 5 (Limiting Use).
Q: Does FINTRAC compliance replace our privacy programme? A: No — FINTRAC creates specific obligations that PIPEDA accommodates through its required-by-law exceptions (for example, consent) for AML data. But PIPEDA continues to apply in full to all other personal information you collect, including the broader client relationship data beyond KYC requirements.
Navigate AML and Privacy with Confidence
Canada Compliance AI helps Canadian businesses in regulated industries manage both their AML compliance obligations and their PIPEDA requirements — clearly separating what each law requires.
Start your free trial today — compliance for the full Canadian regulatory picture.
Related reading: PIPEDA Compliance Guide | PIPEDA for Accounting Firms | Cost of PIPEDA Non-Compliance
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Bill C-27 and AIDA: What Canada Proposed for AI Regulation, and Why It Died
Bill C-27 and AIDA died on the Order Paper in January 2025 and never became law. What they proposed,...
PIPEDA's 10 Principles Explained, With Examples
PIPEDA's 10 fair information principles explained one by one, with what each asks of a small busines...