This policy governs compliance for Consortium Hypothécaire. It must be applied diligently and used as a tool to support the practice of autonomous mortgage brokers and firms in meeting AMF requirements.
The person responsible for this policy is the Chief Privacy Officer, Mr. Jean-François Choquette. The CPO’s title and contact information are published on the Consortium Hypothécaire website.
Consortium Hypothécaire staff must comply with this policy and implement security measures with the CPO’s support.
Personal information is any information about a natural person that allows that person to be identified directly or indirectly.
Data becomes personal information at collection if, combined with other information, it can identify a person.
Examples include name, income, banking information, social insurance number, civic address, credit report, IP address, date of birth, ID documents, and more.
Business contact information (name, title, business address, work email, and work phone) is generally not personal information under Quebec’s Act respecting the protection of personal information in the private sector.
Protection obligations apply regardless of medium (written, graphic, audio, visual, electronic, or other).
Information is sensitive when, by its nature (for example medical or biometric) or context of use or disclosure, it gives rise to a high reasonable expectation of privacy.
Employees must sign confidentiality agreements. Service providers with access to personal information must commit contractually to confidentiality. Mortgage brokers must obtain written, signed client authorization to collect, use, disclose, and retain personal information related to the client, their business, or employees where applicable.
Personal information may be collected only where there is a serious and legitimate interest; collection must be lawful. Individuals must be informed of purposes, means of collection, access and rectification rights, and withdrawal of consent where applicable.
Personal information is used only for purposes for which it was collected unless consent provides otherwise or the law permits. Disclosure to third parties requires client authorization except where the law permits. Access within files is limited to employees who need the information to perform their duties.
Personal information must be retained and destroyed securely, inactive files must be managed according to policy retention rules, and individuals may access and request correction of their information subject to legal requirements.
When a confidentiality incident involving personal information occurs, reasonable measures must be taken promptly to mitigate harm and prevent recurrence. Incidents must be assessed for risk of serious injury; where required, affected individuals and the Commission d’accès à l’information du Québec must be notified. Records of incidents are maintained.
This policy must be reviewed periodically; external review recommendations are incorporated where applicable. This compliance policy has been in effect since December 17, 2020, and was last updated April 22, 2025.
This page is an English overview. The authoritative, full legal text is maintained in French for Consortium Hypothécaire and may be consulted on the French version of this site or by contacting the privacy officer below.