One of the most overlooked aspects of privacy is data retention — how long you keep personal information. Holding data longer than necessary creates risk without benefit.

The Retention Principle

Under PIPEDA, personal information must be retained only as long as necessary to fulfill the purpose for which it was collected. Once that purpose is fulfilled, the information should be destroyed, erased, or made anonymous.

Retention Schedules

A retention schedule is a documented policy that specifies how long different types of information are kept. For example: customer transaction records might be kept for seven years for tax purposes; employee records might be kept for two years after employment ends; marketing contact lists might be reviewed annually and purged of inactive contacts.

Legal Requirements

Some retention periods are set by law. The Income Tax Act requires financial records to be kept for six years. Employment standards legislation sets minimum retention periods for payroll records. Privacy law sets maximum retention periods for personal information. Your retention schedule must comply with both minimums and maximums.

Secure Deletion

Deleting a file does not necessarily destroy the data. Proper data destruction requires overwriting storage media, using certified destruction services for physical media, or cryptographic erasure for encrypted data. Document your destruction process.

Retention and Backups

Backup systems can inadvertently extend retention beyond policy. If your retention policy says delete after two years but your backups are kept for five years, personal information may persist in backups. Your retention policy must address backup systems explicitly.

Next Step

Learn how to build privacy in from the start in Privacy by Design.

← Consent Privacy by Design →