Compliance How-To

Data Retention Policy for Canadian Businesses: What to Keep and When to Delete

How long to keep personal information under PIPEDA: legal retention requirements, a retention schedule for common data types and secure destruction.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
12 min read
Data Retention Policy Canada
PIPEDA Retention
Canadian Records Retention
How Long to Keep Records
Data Destruction Canada

"Keep everything forever" is not a data retention strategy — it's a liability. PIPEDA's limiting retention principle requires retaining personal information only as long as necessary to fulfill the purpose for which it was collected. But "necessary" intersects with other legal requirements (CRA's six-year rule, employment standards, limitation periods) that create minimum retention floors. Here's how to navigate it all.

Last updated: April 2026

The Two-Part Retention Problem

Businesses face two competing pressures:

PIPEDA says: Delete personal information when it's no longer needed for its original purpose.

Other laws say: Keep these records for specific minimum periods.

The solution: A retention schedule that sets the maximum of (a) the period needed for the original purpose and (b) any legally mandated minimum — then deletes at the end of that period.

Legal Retention Requirements in Canada

CRA (Canada Revenue Agency) — The 6-Year Baseline

The Income Tax Act (s. 230(4)) requires businesses to retain records that support tax filings for 6 years from the end of the last tax year they relate to (CRA guidance). Some businesses keep records for 7 years as a buffer, but the legal baseline is 6 years.

This applies to:

  • Invoices and receipts
  • Payroll records
  • Financial statements
  • Purchase and sales records
  • Expense records

PIPEDA implication: Personal information in tax records (employee payroll data, client billing information) must be retained for at least 7 years regardless of what PIPEDA alone might suggest.

Employment Standards — Provincial Variation

Provincial employment standards legislation requires employers to retain employment records:

ProvinceMinimum Retention
Ontario3 years from end of employment
Alberta3 years from end of employment
BC4 years from end of employment
Quebec1 year from end of employment (but CRA's 7 years for payroll overrides this for financial records)

Employment records include: time worked, wages paid, and other standards compliance records. Personnel files with performance evaluations may have different (longer) retention needs based on employment law.

Limitation Periods — The Lawsuit Window

When can someone sue you? Limitation periods set the window. Retention during the limitation period makes evidence available for defence.

Type of ClaimLimitation Period
Contract disputes2 years (Ontario, BC, Alberta basic limitation)
Tort claims2 years (basic limitation)
Personal injury2 years (with some exceptions)
Employment standards complaintsVaries by province (1-2 years typically)
Ultimate limitation15 years from when events occurred (Ontario)

Practical advice: Retain records that could be relevant to a lawsuit for at least 2 years after the relevant relationship ends, plus the time remaining on any applicable limitation period. For high-value contracts or potentially contentious matters, consider 6-7 years.

Regulated Industry Requirements

Some industries have specific retention requirements:

  • Healthcare (PHIPA Ontario, HIA Alberta): Patient records retained for 10 years from last contact, 10 years after a minor turns 18
  • Pharmacies: Prescription records — varies by province (generally 5-10 years)
  • Financial advisors (OSC regulated): Client files and trade records — 7 years
  • Mortgage brokers: Transaction records — 7 years (varies by province)
  • Real estate: Trust account records — 5-7 years (varies by province)
  • Law firms: Client files — 10 years (most provincial law societies)

Retention Schedule for Common Data Types

Customer Data

Data TypeMinimum RetentionMaximum Recommendation
Customer contact information (active customer)Duration of relationshipDuration + 2 years
Customer contact information (inactive customer)None required2-3 years after last contact
Transaction/purchase history7 years (CRA)7 years from transaction
Customer complaint records2 years from resolution5 years
Access/correction requests2 years from response3 years
Marketing consent records3 years from last marketing send3 years from last send

Employee Data

Data TypeMinimum RetentionMaximum Recommendation
Payroll records7 years (CRA)7 years
T4 and ROE copies7 years (CRA)7 years
Employment contract7 years after employment ends7 years
Performance reviews2-3 years after employment ends5 years
Disciplinary recordsDuration of employment + 2 years5 years after employment ends
Medical/accommodation recordsDuration of employment7 years (or as required by WCB)
Criminal record checksDuration of employmentDelete at end of employment
Training recordsDuration of employment5 years

Financial Records

Data TypeMinimum Retention
Invoices7 years
Receipts7 years
Bank statements7 years
Contract copies7 years after contract ends
Cheque copies7 years
Expense reports7 years

Digital and Website Data

Data TypeRecommended Retention
Website analytics (identifiable)12-26 months (then anonymise)
Contact form submissions2-3 years from last contact
Email campaign send records3 years
CASL consent records3 years after last marketing send
Server access logs30-90 days (unless needed for a specific incident)
Security camera footage30-60 days (unless retained for incident)

Building Your Retention Schedule

Step 1: Conduct a Data Inventory

You can't create a retention schedule for data you don't know you have. Map:

  • What personal information you collect
  • Why you collected it (the purpose)
  • Where it's stored
  • Who is responsible for managing it

Step 2: Identify Legal Minimums for Each Data Type

For each data category:

  • Check the CRA's retention requirements
  • Check provincial employment standards
  • Check any industry-specific requirements
  • Check relevant limitation periods

Step 3: Set Retention Periods

The retention period for each category should be the maximum of:

  • The period needed to serve the original collection purpose
  • The legally mandated minimum

Add a small buffer (3-6 months) after the calculated minimum before deletion to account for administrative processes.

Step 4: Assign Ownership

Every data category should have an assigned owner responsible for:

  • Ensuring the data is retained per the schedule
  • Triggering deletion when the retention period expires
  • Documenting the destruction when it occurs

Step 5: Implement the Schedule

For digital data:

  • Configure auto-deletion in cloud systems where available (Slack, HubSpot, WooCommerce)
  • Set calendar reminders for manual deletion tasks
  • Use data lifecycle management features in your CRM, HRIS, or database

For physical records:

  • Use a physical records destruction schedule
  • Use a certified shredding service for sensitive personal information
  • Obtain destruction certificates for highly sensitive records (health records, financial records)

Step 6: Document Destruction

When data is deleted or destroyed:

  • Record what was destroyed, when, and how
  • Retain destruction certificates from shredding services
  • Keep this log itself for at least 7 years

Secure Destruction of Personal Information

"Deleting" files isn't enough for sensitive data. PIPEDA's security safeguard principle requires that destruction be secure.

Electronic Data

  • Standard deletion (Recycle Bin) — does NOT securely destroy data
  • Overwriting — use certified data erasure software (DBAN, Blancco, manufacturer secure erase)
  • Encryption-then-delete — if data was encrypted, deleting the encryption key effectively destroys the data
  • Physical destruction — degaussing or physical shredding of drives for highly sensitive data
  • Cloud data — use the platform's built-in deletion features and confirm data is deleted from backups within the vendor's retention window

Paper Records

  • Use a certified shredding service for personal information
  • Cross-cut shredding minimum for sensitive records
  • For highly sensitive records (health, financial, legal), use a certified document destruction service with a destruction certificate

Photographs and Videos

  • CCTV footage: configure automatic overwriting
  • Employee photos, customer photos: delete from all systems including backups

Frequently Asked Questions

Q: Can we anonymise data instead of deleting it? A: Yes — truly anonymised data is no longer personal information under PIPEDA, so it can be retained without the same limits. But ensure the anonymisation is genuine — the bar for true anonymisation is high, and re-identification risk from data combinations must be assessed.

Q: Our accounting software retains everything for 7 years automatically. Is that compliant? A: For financial records covered by CRA's 7-year rule — yes, this is appropriate. For personal information in the accounting system that doesn't need to be retained for tax purposes, the 7-year default may retain data longer than necessary. Assess what's in your accounting system and whether all of it serves the tax compliance purpose.

Q: We back up our data to offsite storage. Do backup copies count for retention? A: Yes — personal information in backups is still personal information subject to PIPEDA. Your retention schedule should address both live and backup data. Configure your backup system to purge data matching your retention schedule.


Know What to Keep. Know When to Delete.

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — data retention compliance that's actually manageable.

Related reading: Privacy Audit Checklist Canada | PIPEDA Compliance Guide | PIPEDA 10 Principles

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.