Personal information protection policy

Preamble

This policy governs compliance for Consortium Hypothécaire. It must be applied diligently and used as a tool to support the practice of autonomous mortgage brokers and firms in meeting AMF requirements.

Purpose of the policies

  1. Set general principles for collecting, using, and disclosing personal information;
  2. Retain data appropriately;
  3. Destroy personal information appropriately;
  4. Anonymize personal information where applicable;
  5. Receive and handle complaints and requests from individuals exercising their rights;
  6. Secure data appropriately;
  7. Manage confidentiality incidents and incident response plans.

Objectives

  1. Ensure that protecting our clients’ personal information is and remains a priority;
  2. Ensure reasonable measures protect personal information that is collected, used, disclosed, retained, or destroyed, based on sensitivity, purpose, volume, distribution, and medium.

1. Roles and responsibilities

The person responsible for this policy is the Chief Privacy Officer, Mr. Jean-François Choquette. The CPO’s title and contact information are published on the Consortium Hypothécaire website.

Consortium Hypothécaire staff must comply with this policy and implement security measures with the CPO’s support.

2. Definition of personal information

Personal information is any information about a natural person that allows that person to be identified directly or indirectly.

Data becomes personal information at collection if, combined with other information, it can identify a person.

Examples include name, income, banking information, social insurance number, civic address, credit report, IP address, date of birth, ID documents, and more.

Business contact information (name, title, business address, work email, and work phone) is generally not personal information under Quebec’s Act respecting the protection of personal information in the private sector.

Protection obligations apply regardless of medium (written, graphic, audio, visual, electronic, or other).

3. Sensitive personal information

Information is sensitive when, by its nature (for example medical or biometric) or context of use or disclosure, it gives rise to a high reasonable expectation of privacy.

4–6. Employment, service agreements, and consent

Employees must sign confidentiality agreements. Service providers with access to personal information must commit contractually to confidentiality. Mortgage brokers must obtain written, signed client authorization to collect, use, disclose, and retain personal information related to the client, their business, or employees where applicable.

7. Collection, use, and disclosure

Personal information may be collected only where there is a serious and legitimate interest; collection must be lawful. Individuals must be informed of purposes, means of collection, access and rectification rights, and withdrawal of consent where applicable.

Personal information is used only for purposes for which it was collected unless consent provides otherwise or the law permits. Disclosure to third parties requires client authorization except where the law permits. Access within files is limited to employees who need the information to perform their duties.

Personal information must be retained and destroyed securely, inactive files must be managed according to policy retention rules, and individuals may access and request correction of their information subject to legal requirements.

Confidentiality incidents

When a confidentiality incident involving personal information occurs, reasonable measures must be taken promptly to mitigate harm and prevent recurrence. Incidents must be assessed for risk of serious injury; where required, affected individuals and the Commission d’accès à l’information du Québec must be notified. Records of incidents are maintained.

Policy review

This policy must be reviewed periodically; external review recommendations are incorporated where applicable. This compliance policy has been in effect since December 17, 2020, and was last updated April 22, 2025.

This page is an English overview. The authoritative, full legal text is maintained in French for Consortium Hypothécaire and may be consulted on the French version of this site or by contacting the privacy officer below.


What you should know about our personal information protection policy:

  • Our policy covers roles and responsibilities, hiring, consent, service agreements, and general principles for collecting, using, and disclosing personal information. It addresses retention, inactive files, secure destruction and anonymization, complaints and access requests, data security, backups, passwords, incidents, third-party IT support, and identity theft.
  • The person responsible for this policy is Mr. Jean-François Choquette, reachable at info@consortiumhypothecaire.com and/or 418-204-7738.
  • If a confidentiality incident occurs, our incident management process is activated automatically.
  • We also have a complaints process related to the confidentiality of your personal information.
  • The same person handles complaints and incidents and can be reached at the coordinates above.
  • Through this policy, our organization commits to protecting your information appropriately.
  • For questions about this policy, contact the responsible person at the coordinates above.