How to send sensitive documents securely in Canada
How to send sensitive documents securely in Canada
Most advice on this topic stops at "don't use email", which is not helpful when a mortgage broker needs your notice of assessment by Thursday.
So here is a ranked list of what to actually do, in order of preference, with the realistic trade-offs.
First: send less
Before choosing a channel, ask what the recipient actually needs. A surprising share of document requests are habit rather than requirement.
- Do they need the document, or the information in it? A form that needs your account number does not need a bank statement.
- Do they need every page? Send the two that matter.
- Do they need every field? Redact balances, unrelated transactions, other people's names, and anything outside the request.
- Do they need it, or do they need to see it? Some verifications can be done in person or over a video call.
Every reduction here is worth more than any encryption decision that follows it.
The ranking
1. The recipient's own secure portal — best
Banks, credit unions, mortgage brokers, insurers, law firms, accountants, immigration consultants, property managers and healthcare providers in Canada almost all have a secure document upload channel, because their regulators and their insurers require it.
The problem is that the person who emailed you often did not mention it. Ask explicitly: "Do you have a secure upload portal or a document request link?" The answer is usually yes.
Why it ranks first: the document lands directly in their file system, is covered by their retention and security policies, and never sits in a mailbox.
2. An expiring, access-controlled link — very good
A link that is restricted to a named person and expires on a date is a strong option, and it is the model most modern document tools use.
What makes it work:
- restricted to a specific recipient, not "anyone with the link"
- an expiry date
- a record of who opened it and when
- the ability to revoke it
What makes it useless: setting it to "anyone with the link" and leaving it live forever. That is a public URL with extra steps, and those links get forwarded, pasted into tickets, and occasionally indexed.
3. A password-protected file — good, with one rule
Encrypt the file itself, then send it however you like.
The rule: the password must travel by a different channel. Phone call or text, never the same email and never a follow-up email. A password in the same thread offers no protection whatsoever — an attacker reading the mailbox reads both.
See How to password-protect a PDF before you send it.
4. End-to-end encrypted messaging — acceptable
Better than email for transport. Two caveats: the image usually lands in the recipient's camera roll and syncs to their cloud, and it persists there indefinitely. Fine for a one-off; poor as a habit.
5. Plain email attachment — last resort
Everything in Is it safe to email your SIN, passport or ID? applies. If it is genuinely the only option, apply the password rule above.
Not ranked: fax
Still common in Canadian healthcare and legal practice. It is not encrypted, and misdialled faxes are a well-documented source of disclosure. Use it when the recipient can accept nothing else, not because it feels official.
What to ask the recipient
Four questions, all reasonable, all rarely asked:
- "Do you have a secure upload channel?"
- "Which specific pages do you need?"
- "How long do you keep this, and can you delete it when the file closes?"
- "Who inside your organization will have access?"
A legitimate business will answer all four without friction. Hesitation on the third and fourth is informative.
Keep a record
If a document is later misused, the first useful question is where it went. Keep a simple log:
| What | To whom | Date | Why | Deleted? |
|---|---|---|---|---|
| Passport pp. 1–2 | Maple Property Mgmt | 2026-08-04 | Rental application | Requested |
Manual is fine. Automatic is better — some tools keep this for you.
Special cases
Government submissions. Use the government's own portal — CRA My Account, IRCC secure account, ServiceOntario. Never email documents to a government address unless that address was published for the purpose, and be alert to lookalike domains. See How to spot a fake government website.
Job applications. Employers need your CV, not your SIN, passport or date of birth — those come after an offer, through HR's own onboarding system. A recruiter asking for a SIN before an offer is a warning sign.
Landlords. They may verify identity and income. Handing over full bank statements and a passport scan by email to a stranger you met through a listing site is a genuine risk. Show, do not send, where possible.
Healthcare. Providers are bound by health privacy legislation and generally have secure channels. Ask.
How my-id.ca helps
my-id.ca attacks the top of this page rather than the bottom: instead of finding a safer way to send documents, it removes many of the sends.
Your saved profile fills forms directly — web forms through the Chrome extension, PDFs in the app — so the information reaches the form without a file moving anywhere. When a business does need documents, they can request them through my-id.ca, which is an access-controlled channel with a record of exactly what you shared — the log this article recommends, kept automatically.
Files are encrypted, stored on Canadian servers, and searched by my-id.ca's own AI rather than a third-party provider.
Next steps
- Is it safe to email your SIN, passport or ID?
- How to password-protect a PDF before you send it
- What to send a realtor, broker or consultant — and what not to
- What a business can and cannot see
Important: this is general information, not legal advice
This article is general information about handling your own documents — it is not legal, security, or financial advice, and my-id.ca does not provide legal or professional consultation. my-id.ca is not a government agency, law firm, lawyer, or licensed advisor, and is not affiliated with or endorsed by the Government of Canada, the Government of Ontario, the Office of the Privacy Commissioner of Canada, or any regulator.
Security practices and privacy obligations differ by organization and change over time. Confirm the current guidance on the official sources, including the Office of the Privacy Commissioner of Canada and canada.ca. For advice about your individual circumstances, consult a qualified professional. If anything in this guide differs from an official source, the official source is correct.
Frequently asked questions
- What is the safest way to send a document to a bank or broker?
- Their own secure upload portal. Regulated businesses in Canada almost always have one because their regulators and insurers require it. Ask for it by name — front-line staff frequently default to email out of habit.
- Is a Google Drive or Dropbox link safe enough?
- Better than an attachment if the link is restricted to a specific person and set to expire. A link set to 'anyone with the link' is effectively public, is often indexed or forwarded, and typically stays live long after the matter is closed.
- Should I password-protect the file?
- Yes, if you must send it as an attachment — but the password must travel by a different channel. A password sent in the same email, or in a follow-up email, provides no protection at all.
- Is fax still used in Canada, and is it secure?
- Fax remains common in healthcare and legal settings. It is not encrypted, and misdialled faxes are a well-documented source of disclosure. It is not more secure than a modern portal, only more familiar.
- How do I send a document to someone who is not technical?
- Use whatever secure channel they already have — a portal from their bank or lawyer, or an expiring link they only need to click. Adding new software to the process usually means they fall back to email.
- Should I keep a record of what I sent?
- Yes. If a document is later misused, the first useful question is where it went. A simple log of document, recipient, date and purpose is enough, and some tools keep it automatically.