Data Retention Policy for Canadian Businesses: What to Keep and When to Delete
How long to keep personal information under PIPEDA: legal retention requirements, a retention schedule for common data types and secure destruction.
"Keep everything forever" is not a data retention strategy — it's a liability. PIPEDA's limiting retention principle requires retaining personal information only as long as necessary to fulfill the purpose for which it was collected. But "necessary" intersects with other legal requirements (CRA's six-year rule, employment standards, limitation periods) that create minimum retention floors. Here's how to navigate it all.
Last updated: April 2026
The Two-Part Retention Problem
Businesses face two competing pressures:
PIPEDA says: Delete personal information when it's no longer needed for its original purpose.
Other laws say: Keep these records for specific minimum periods.
The solution: A retention schedule that sets the maximum of (a) the period needed for the original purpose and (b) any legally mandated minimum — then deletes at the end of that period.
Legal Retention Requirements in Canada
CRA (Canada Revenue Agency) — The 6-Year Baseline
The Income Tax Act (s. 230(4)) requires businesses to retain records that support tax filings for 6 years from the end of the last tax year they relate to (CRA guidance). Some businesses keep records for 7 years as a buffer, but the legal baseline is 6 years.
This applies to:
- Invoices and receipts
- Payroll records
- Financial statements
- Purchase and sales records
- Expense records
PIPEDA implication: Personal information in tax records (employee payroll data, client billing information) must be retained for at least 7 years regardless of what PIPEDA alone might suggest.
Employment Standards — Provincial Variation
Provincial employment standards legislation requires employers to retain employment records:
| Province | Minimum Retention |
|---|---|
| Ontario | 3 years from end of employment |
| Alberta | 3 years from end of employment |
| BC | 4 years from end of employment |
| Quebec | 1 year from end of employment (but CRA's 7 years for payroll overrides this for financial records) |
Employment records include: time worked, wages paid, and other standards compliance records. Personnel files with performance evaluations may have different (longer) retention needs based on employment law.
Limitation Periods — The Lawsuit Window
When can someone sue you? Limitation periods set the window. Retention during the limitation period makes evidence available for defence.
| Type of Claim | Limitation Period |
|---|---|
| Contract disputes | 2 years (Ontario, BC, Alberta basic limitation) |
| Tort claims | 2 years (basic limitation) |
| Personal injury | 2 years (with some exceptions) |
| Employment standards complaints | Varies by province (1-2 years typically) |
| Ultimate limitation | 15 years from when events occurred (Ontario) |
Practical advice: Retain records that could be relevant to a lawsuit for at least 2 years after the relevant relationship ends, plus the time remaining on any applicable limitation period. For high-value contracts or potentially contentious matters, consider 6-7 years.
Regulated Industry Requirements
Some industries have specific retention requirements:
- Healthcare (PHIPA Ontario, HIA Alberta): Patient records retained for 10 years from last contact, 10 years after a minor turns 18
- Pharmacies: Prescription records — varies by province (generally 5-10 years)
- Financial advisors (OSC regulated): Client files and trade records — 7 years
- Mortgage brokers: Transaction records — 7 years (varies by province)
- Real estate: Trust account records — 5-7 years (varies by province)
- Law firms: Client files — 10 years (most provincial law societies)
Retention Schedule for Common Data Types
Customer Data
| Data Type | Minimum Retention | Maximum Recommendation |
|---|---|---|
| Customer contact information (active customer) | Duration of relationship | Duration + 2 years |
| Customer contact information (inactive customer) | None required | 2-3 years after last contact |
| Transaction/purchase history | 7 years (CRA) | 7 years from transaction |
| Customer complaint records | 2 years from resolution | 5 years |
| Access/correction requests | 2 years from response | 3 years |
| Marketing consent records | 3 years from last marketing send | 3 years from last send |
Employee Data
| Data Type | Minimum Retention | Maximum Recommendation |
|---|---|---|
| Payroll records | 7 years (CRA) | 7 years |
| T4 and ROE copies | 7 years (CRA) | 7 years |
| Employment contract | 7 years after employment ends | 7 years |
| Performance reviews | 2-3 years after employment ends | 5 years |
| Disciplinary records | Duration of employment + 2 years | 5 years after employment ends |
| Medical/accommodation records | Duration of employment | 7 years (or as required by WCB) |
| Criminal record checks | Duration of employment | Delete at end of employment |
| Training records | Duration of employment | 5 years |
Financial Records
| Data Type | Minimum Retention |
|---|---|
| Invoices | 7 years |
| Receipts | 7 years |
| Bank statements | 7 years |
| Contract copies | 7 years after contract ends |
| Cheque copies | 7 years |
| Expense reports | 7 years |
Digital and Website Data
| Data Type | Recommended Retention |
|---|---|
| Website analytics (identifiable) | 12-26 months (then anonymise) |
| Contact form submissions | 2-3 years from last contact |
| Email campaign send records | 3 years |
| CASL consent records | 3 years after last marketing send |
| Server access logs | 30-90 days (unless needed for a specific incident) |
| Security camera footage | 30-60 days (unless retained for incident) |
Building Your Retention Schedule
Step 1: Conduct a Data Inventory
You can't create a retention schedule for data you don't know you have. Map:
- What personal information you collect
- Why you collected it (the purpose)
- Where it's stored
- Who is responsible for managing it
Step 2: Identify Legal Minimums for Each Data Type
For each data category:
- Check the CRA's retention requirements
- Check provincial employment standards
- Check any industry-specific requirements
- Check relevant limitation periods
Step 3: Set Retention Periods
The retention period for each category should be the maximum of:
- The period needed to serve the original collection purpose
- The legally mandated minimum
Add a small buffer (3-6 months) after the calculated minimum before deletion to account for administrative processes.
Step 4: Assign Ownership
Every data category should have an assigned owner responsible for:
- Ensuring the data is retained per the schedule
- Triggering deletion when the retention period expires
- Documenting the destruction when it occurs
Step 5: Implement the Schedule
For digital data:
- Configure auto-deletion in cloud systems where available (Slack, HubSpot, WooCommerce)
- Set calendar reminders for manual deletion tasks
- Use data lifecycle management features in your CRM, HRIS, or database
For physical records:
- Use a physical records destruction schedule
- Use a certified shredding service for sensitive personal information
- Obtain destruction certificates for highly sensitive records (health records, financial records)
Step 6: Document Destruction
When data is deleted or destroyed:
- Record what was destroyed, when, and how
- Retain destruction certificates from shredding services
- Keep this log itself for at least 7 years
Secure Destruction of Personal Information
"Deleting" files isn't enough for sensitive data. PIPEDA's security safeguard principle requires that destruction be secure.
Electronic Data
- Standard deletion (Recycle Bin) — does NOT securely destroy data
- Overwriting — use certified data erasure software (DBAN, Blancco, manufacturer secure erase)
- Encryption-then-delete — if data was encrypted, deleting the encryption key effectively destroys the data
- Physical destruction — degaussing or physical shredding of drives for highly sensitive data
- Cloud data — use the platform's built-in deletion features and confirm data is deleted from backups within the vendor's retention window
Paper Records
- Use a certified shredding service for personal information
- Cross-cut shredding minimum for sensitive records
- For highly sensitive records (health, financial, legal), use a certified document destruction service with a destruction certificate
Photographs and Videos
- CCTV footage: configure automatic overwriting
- Employee photos, customer photos: delete from all systems including backups
Frequently Asked Questions
Q: Can we anonymise data instead of deleting it? A: Yes — truly anonymised data is no longer personal information under PIPEDA, so it can be retained without the same limits. But ensure the anonymisation is genuine — the bar for true anonymisation is high, and re-identification risk from data combinations must be assessed.
Q: Our accounting software retains everything for 7 years automatically. Is that compliant? A: For financial records covered by CRA's 7-year rule — yes, this is appropriate. For personal information in the accounting system that doesn't need to be retained for tax purposes, the 7-year default may retain data longer than necessary. Assess what's in your accounting system and whether all of it serves the tax compliance purpose.
Q: We back up our data to offsite storage. Do backup copies count for retention? A: Yes — personal information in backups is still personal information subject to PIPEDA. Your retention schedule should address both live and backup data. Configure your backup system to purge data matching your retention schedule.
Know What to Keep. Know When to Delete.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — data retention compliance that's actually manageable.
Related reading: Privacy Audit Checklist Canada | PIPEDA Compliance Guide | PIPEDA 10 Principles
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
How to Respond to a Privacy Complaint in Canada: Step-by-Step Guide
Received a privacy complaint or an OPC notice? How the investigation process works, what to send, an...
CASL-Compliant Email Templates for Canadian Businesses
CASL-compliant email templates for Canadian businesses: welcome messages, re-consent campaigns, unsu...