The Security Risks of Storing Corporate Records Yourself
Corporate minute books hold some of the most sensitive personal data your company controls — director SINs, residential addresses, beneficial ownership, full cap tables. Storing them on shared drives, email threads, or unmanaged document portals does not meet the reasonable-safeguards standard Canadian privacy law expects. Here's what's at stake, and how Corpbook closes the gap.
Corporate records don’t feel like a cybersecurity problem. They’re PDFs and spreadsheets — not payment data, not medical records. So most small and mid-size companies store them wherever is convenient: a shared Google Drive folder, a law firm’s document portal, an email thread from the day of incorporation.
That approach carries more risk than most founders realize — and more legal exposure than most lawyers mention upfront.
What’s actually in your corporate records?
Before assessing the risk, it helps to be precise about what minute books and compliance registers contain.
A complete corporate record set includes:
- Full legal names, residential addresses, and dates of birth of every director, officer, shareholder, and significant individual
- SINs or equivalent tax identification numbers New requirements mandate the collection of sensitive individual data for certain filings and beneficial ownership records. Many companies don’t even realize their legal obligation to collect and store this data in the first place, let alone secure it!
- Percentage ownership and share class holdings for every shareholder — current and historical
- Transparency register entries, including the names, addresses, and ownership percentages of all individuals with significant control (ISC) — required under BC’s Business Corporations Act and the federal Canada Business Corporations Act
- Bank signatories, signing authorities, and officer roles — i.e., who can commit the company to obligations
- Historical cap table data — who owned what, when they sold, and at what valuation
Taken together, this is a comprehensive profile of every person materially connected to your business. In the wrong hands, it enables identity fraud, targeted phishing, extortion, and competitive intelligence gathering.
The specific risks of DIY storage
1. Shared drives with no access controls
Google Drive and SharePoint make sharing easy. That’s also the problem. Folders get shared broadly for convenience, ex-employees retain access after offboarding, and there’s rarely any audit trail showing who viewed a document. A departing shareholder or disgruntled former officer who still has a link can access your full director register without you knowing.
2. Email as a filing system
“Just email me the signed resolution” is the most common records-management practice for small companies. Email is unencrypted in transit by default, retained indefinitely, replicated across multiple mail servers, and frequently included in e-discovery or forwarded without thought. Signed director resolutions and share certificates attached to emails from five years ago are sitting in someone’s Gmail inbox right now, protected by whatever password they set in 2007 that got leaked in unrelated data breaches.
3. Unencrypted local files and backups
Corporate documents stored locally — on an assistant’s laptop, a founding partner’s desktop — are one stolen device away from a full disclosure. If those files are backed up to iCloud or a personal Dropbox, they’re subject to whatever authentication and breach history those accounts have. There is no access log, no remote wipe path for the documents themselves, and no way to know who has copies.
4. No audit trail means no way to detect a breach
Even if your records aren’t actively stolen, unauthorized access may go undetected indefinitely. Without per-document access logging, you have no way to know if someone viewed your transparency register, your cap table, or your director list — let alone when, from where, or how often.
5. Law firm portals with inherited risk
Many companies leave their records at their incorporation lawyer’s firm. The lawyer is trustworthy — but their document management software may not be. Law firms are active targets for ransomware and data breaches, precisely because they hold sensitive records across hundreds of clients. One compromised credential at the firm exposes not just your records but every client’s. You bear the consequence; you had no say in their security posture.
It’s worth being direct here: any platform that aggregates corporate records across many companies — Corpbook included — is an attractive target for the same reason. Concentration of sensitive data attracts attackers regardless of who holds it. The question is not whether a custodian is a target, but how prepared they are to be one. A law firm’s core competency is legal practice; security is a cost centre, typically outsourced to whichever IT vendor the firm contracts with — and digitally unsophisticated firms often store client records in insecure email chains, unversioned Word documents, and shared spreadsheets nobody owns. Corpbook is the opposite: corporate records are the product, and the controls protecting them — encryption, scoped access, immutable audit logs, monitoring, breach response, independent review — are engineering work we do daily, not a checkbox bolted onto unrelated practice-management software. Same threat, different posture.
Why this matters legally, not just operationally
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (PIPA), and similar acts across Canadian provinces apply to personal information held by private-sector organizations. Director and shareholder data — names, addresses, dates of birth, government id numbers, and ownership percentages — are personal information under both statutes.
If that data is breached due to inadequate safeguards, your company may be required to:
- Notify affected individuals
- Report to the applicable Privacy Commissioner
- Demonstrate that reasonable security measures were in place
“We kept it in a shared Drive where anyone with the link can access it” is unlikely to satisfy the reasonable safeguards standard, particularly if the breach was foreseeable. Offence provisions under PIPEDA (s. 28) and PIPA BC (s. 56) carry the prospect of statutory fines on top of the reputational and contractual exposure a breach creates.
The BC Transparency Register, Federal ISC (Individuals with Significant Control) Register and other beneficial ownership registers add a further dimension: some registers require sensitive citizenship or tax numbers, the data must be kept accurate on timelines as short as two weeks on personal information changes, retained for a period after an individual ceases to be an ISC, and produced on request to certain government authorities. Inadequate storage practices compromise your ability to meet these obligations.
How Corpbook closes the gap
Corpbook is built end-to-end for Canadian corporate records — minute books, director and officer registers, share and cap table records, transparency / ISC register management, resolutions, meeting records, and ongoing compliance tracking. Every control described below exists because the records themselves are the product, not an attachment to it.
What that looks like in practice:
- Statutory registers as first-class data, not files. Directors, officers, shareholders, share classes, ISC determinations, and ownership history are structured records the system understands — validated against the rules of your governing statute, queryable, and produced on demand in the format government registries expect. No more hunting through folders for the current version of the register.
- Transparency / ISC register tooling. Corpbook calculates the 25% control thresholds, generates the secure shareholder questionnaires you’re required to send, collects the responses, flags inconsistencies between the transparency register and the underlying director and shareholder records, schedules annual confirmation reminders, and stores the register in the form required by BC’s Business Corporations Act and the federal Canada Business Corporations Act — so when you sit down to file or respond to a government request, the data is already in the right shape.
- Resolutions and meeting records that are actually findable. Director and shareholder resolutions, notices of meeting, minutes, and consents live alongside the registers they affect, with the people, dates, and authorisations linked together. A diligence request that would take a week of email archaeology takes a search box.
- Immutable audit logs on every record. Every view, edit, and download is recorded with timestamp, user identity, and IP address — kept in append-only storage so the log itself can’t be quietly altered. This is the evidence trail you need to demonstrate reasonable safeguards under PIPEDA and PIPA if you ever have to.
- Encrypted in transit and at the storage layer, by default, on every record. TLS everywhere; encrypted storage underneath, with row-level access controls on top. There is no “but did someone save a copy to their desktop” path, because the records aren’t shipped around as loose files in the first place.
- Least-privilege access scoped to corporate roles. Access is granted per company and per role — director, officer, advisor, auditor — not by sharing folders. Offboarding revokes everything in one place. There is no equivalent of a stale Google Drive link a former founder can still open.
The DIY alternative isn’t just less secure — it leaves you with no evidence of what you did, who saw what, or when. A shared Drive folder cannot produce an access log. An email archive cannot prove a record was the current one on a given date. Corpbook can.
The practical case
Founders spend significant time on cybersecurity for the product — customer data, infrastructure, API keys. The same rigour rarely reaches corporate records, because the records don’t feel like “the business.”
But your shareholder register and director list contain some of the most concentrated personal data your company holds — and the individuals whose data it is are often your most significant stakeholders: co-founders, investors, board members, and the very people whose trust a breach would damage worst.
Treating that data with the same care you give customer PII isn’t good hygiene. Under PIPEDA, PIPA, and the corporate statutes that govern your registers, it’s the standard you’re already expected to meet. Corpbook is what meeting it looks like in practice — purpose-built for Canadian corporate records, with the controls, registers, and audit trail in place from the moment you create your first company.
Move your corporate records off shared drives and email today.
Start keeping your corporate records the right way
Corpbook gives Canadian companies a complete minute book, director and officer registers, share and cap table records, transparency / ISC register management, resolutions, meeting records, and ongoing compliance tracking — purpose-built and ready from your first login.
Not legal advice
Corpbook is a corporate records, governance, and compliance platform for Canadian companies — covering minute books, director and officer registers, share and cap table records, transparency / ISC register management, resolutions and meeting records, document storage, and ongoing compliance tracking. Posts on this site are for general informational purposes only and do not constitute legal, tax, or financial advice. Nothing on this site should be read as a representation or warranty by Corpbook regarding security outcomes, regulatory compliance, or assumption of liability for any data breach, loss, damages, or regulatory exposure. For advice specific to your situation — including obligations under PIPEDA, PIPA, the Business Corporations Act (BC), the Canada Business Corporations Act, the Business Corporations Act (Ontario), or other applicable corporate or privacy legislation — consult a qualified Canadian corporate lawyer.