Is it safe to email your SIN, passport or ID?
Is it safe to email your SIN, passport or ID?
No. And the reason is worth understanding, because "email is not secure" is repeated so often that it has stopped meaning anything specific.
Here is what specifically happens.
What actually happens to the attachment
When you email a scan of your passport, that file comes to rest in at least four places, indefinitely:
- Your sent folder, synced to every device signed into your account.
- Your mail provider's servers, including their backups.
- The recipient's inbox, and every device they have synced it to.
- The recipient's mail provider's servers, including their backups — and, if the recipient is a business, very likely a compliance archive that retains messages for years by policy.
Add the possibility that the recipient forwards it to a colleague, and that they download it to a laptop, and the count grows.
None of those copies are under your control, and deleting your copy does nothing to the others.
The encryption question
Modern email usually travels over an encrypted connection between mail servers. Two things about that:
- It is opportunistic. If the receiving server does not support encryption, most senders will deliver the message unencrypted anyway rather than fail. You are not told when this happens.
- It protects the message in transit only. At every stop along the way, and at both ends, the message and its attachment sit in readable form.
This is not end-to-end encryption. It is closer to sending a postcard in an envelope that any given post office may or may not bother to use.
The real threat is not interception
Nobody is sitting on a fibre line waiting for your passport scan. The realistic risk is far more mundane, and far more common:
- Your email account gets compromised — through a reused password, a phishing page, or a breach at an unrelated service. Whoever gets in does not read your messages one by one; they search for "passport", "SIN", "void cheque", "T4". Years of documents, in one place, indexed and searchable. This is the single most common way a Canadian's identity documents end up for sale.
- The recipient's account gets compromised, and you never find out.
- The recipient's laptop is lost or stolen with the attachment downloaded.
- It gets forwarded to someone you never agreed to share it with.
- Autocomplete sends it to the wrong person. Type three letters, pick the wrong "Sarah", and your driver's licence is now in a stranger's inbox with no way to recall it.
That last one is not exotic. It is probably the most frequent cause of accidental document disclosure in existence.
"But they asked me to email it"
Very often, they have a better channel and the person who asked you did not mention it.
Ask this question: "Do you have a secure upload portal or document link I can use instead?"
Banks, credit unions, mortgage brokers, law firms, immigration consultants, insurance brokers, accountants and property managers almost all have one — it is required by their own regulators and insurers. The front-line employee asking you for a passport scan is frequently just using the tool they find easiest.
If the answer is genuinely no:
- Put the document in a password-protected file — see How to password-protect a PDF before you send it.
- Send the password by a different channel — a phone call or a text. Never in the same email, and never in a follow-up email, which defeats the entire exercise.
- Send only the pages actually required, not the whole document.
- Redact what is not needed. A proof-of-address request does not need your account balance.
- Ask how long they will retain it, and ask them to delete it when the file closes.
- Write down what you sent, to whom, and when.
The thing nobody tells you: emailing it to yourself is not better
Sending documents to your own inbox to move them between devices feels private. It is not.
Your email account is the most attacked account you own, because it is the password-reset path for your bank, your government accounts, and everything else. It is the account attackers most want, and a passport scan sitting in its archive is exactly what they are looking for once they are in.
If you need your documents on your phone, use something built to hold them.
What to do instead
| Situation | Better option |
|---|---|
| A business needs your documents | Their secure upload portal — ask for it |
| You need documents on your own phone | An encrypted vault app, not your camera roll or inbox |
| You need to give a SIN | Say it out loud, on the phone or in person |
| A one-off share with a person | An expiring, access-controlled link rather than an attachment |
| A form needs your details typed in | Autofill from a stored profile, so the document never moves at all |
That last row is the underrated one. A great deal of document-emailing exists only because someone needs the information inside the document, not the document itself. Filling the fields directly means nothing gets attached to anything.
How my-id.ca helps
my-id.ca exists largely because of the problem on this page. It gives you a free Canadian vault for identity documents that is encrypted, access-controlled, and reachable from any device — so you never need to email a passport scan to yourself to get it onto your phone.
More importantly, it removes most of the reason to send documents at all: your saved profile fills the fields directly on web forms and PDFs, so the information arrives where it is needed without a file changing hands. When you do share with a business, sharing history records what went where — the record this article recommends you keep.
Your files are stored on Canadian servers and searched by my-id.ca's own AI, not sent to OpenAI, Google or Anthropic. See Trust and security.
Next steps
- How to send sensitive documents securely in Canada
- Who can legally ask for your SIN
- What to do if your SIN or ID is stolen
- Is it safe to store my SIN in my-id.ca?
Important: this is general information, not legal advice
This article is general information about handling your own documents — it is not legal, security, or financial advice, and my-id.ca does not provide legal or professional consultation. my-id.ca is not a government agency, law firm, lawyer, or licensed advisor, and is not affiliated with or endorsed by the Government of Canada, the Government of Ontario, the Office of the Privacy Commissioner of Canada, the Canada Revenue Agency, or Service Canada.
Privacy obligations and security practices differ by organization and change over time. Confirm the current guidance on the official sources, including the Office of the Privacy Commissioner of Canada and canada.ca. For advice about your individual circumstances — particularly if you believe your information has been misused — consult a qualified professional. If anything in this guide differs from an official source, the official source is correct.
Frequently asked questions
- Is it safe to email my SIN?
- No. Email travels between servers that may or may not encrypt the connection, and a copy is stored in your sent folder, the recipient's inbox, and on both mail providers' servers indefinitely. A SIN sent by email in 2020 is still sitting in those places today. Give it verbally or through a secure portal instead.
- What if the company asks me to email my documents?
- Ask whether they have a secure upload portal — most banks, brokerages, law firms and government-facing businesses do, and the front-line staff often forget to mention it. If they genuinely have nothing else, send a password-protected file and give the password by phone or text, never in the same email.
- Is emailing a document to myself safe?
- It is the same risk with an extra step. Your own inbox is the most attacked account you own, because it is the reset path for everything else. A passport scan sitting in your own mail archive is one credential-stuffing attack away from being someone else's.
- Is texting a photo of my ID safer than email?
- Somewhat, if the messaging app is end-to-end encrypted — but the photo usually lands in the recipient's camera roll, syncs to their cloud, and stays there. Standard SMS is not encrypted at all.
- How do I know if an email connection was encrypted?
- You generally cannot. Transport encryption between mail servers is opportunistic — it is used when both ends support it and silently skipped when they do not. You have no way to verify what happened after you pressed send.
- Does deleting the email fix it?
- No. Deleting removes it from your view. It does not remove it from the recipient's inbox, from either provider's backups, from any archiving or compliance system the recipient's employer runs, or from a device that already synced it.