The Keep-Forever Trap: Building a Defensible Data Retention Schedule in Canada
The cheapest data to breach is the data you never needed to keep. A defensible retention schedule is the one privacy control that pays for itself the day you delete.
By Valdra Team
A mid-sized recruiting agency in Ontario got breached last year. The attacker pulled a database and walked off with resumes, SINs, reference contacts, the works. The ugly part wasn't the breach itself. It was that 80% of the exposed records belonged to candidates who had applied for jobs between 2009 and 2015 and were never hired. People who, in many cases, had since changed careers, changed provinces, and forgotten the agency existed. The agency had no business holding any of it. They just never deleted anything.
That is the keep-forever trap, and it is the single most common privacy failure I see in Canadian businesses. Storage is cheap, deleting feels risky, and nobody ever got fired for keeping a file. So everything accumulates. Until the day a regulator, a breach, or an access request turns that dusty archive into a liability with your name on it.
Why "we might need it someday" is a legal problem, not just a hygiene one
People treat data retention as an IT housekeeping issue. It isn't. Under PIPEDA, it's a binding obligation. Principle 4.5 of Schedule 1 says personal information "shall be retained only as long as necessary for the fulfilment of those purposes." Principle 4.5.3 goes further: information no longer required to fulfil the identified purposes "should be destroyed, erased, or made anonymous."
Read that again. The default state of personal information under Canadian law is *deletion*. Keeping it is the exception you have to justify, not the other way around. Most companies have the logic backwards. They assume they can hold data indefinitely unless someone tells them to stop, when the law actually says they must dispose of it once the purpose is gone.
The Office of the Privacy Commissioner has made this concrete in its findings. The OPC has held that an organization breached the retention principle simply by lacking a schedule, never mind whether any harm occurred. The absence of a documented, enforced retention practice is itself the finding. You don't get to argue "no harm, no foul." Failing to limit retention *is* the foul.
Quebec raised the stakes further. Law 25 amended the province's private-sector privacy act so that organizations must destroy personal information once the purpose is fulfilled, or anonymize it according to generally accepted best practices. The Commission d'accès à l'information (CAI) can levy administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is greater, and pursue penal fines that climb to $25 million or 4% of turnover. For health information, Ontario's PHIPA layers on its own retention and secure-disposal duties, with the Information and Privacy Commissioner of Ontario watching. None of these regulators is impressed by a server full of data you "might need someday."
What a data retention schedule Canada regulators will actually accept looks like
A retention schedule is not a policy document that says "we keep data only as long as necessary." That sentence is worthless on its own. It restates the obligation without discharging it. A real data retention schedule Canada authorities will accept is a table. It maps every category of personal information you hold to three things: the purpose you collected it for, the specific retention period, and the disposal method.
Here is the shape of it:
- Data category — be granular. "Customer data" is not a category. "Customer billing records," "marketing email subscribers," "support chat transcripts," and "abandoned-cart contact info" are four different categories with four different clocks.
- Purpose and legal basis — why you hold it, tied to an identified purpose or a statutory requirement.
- Retention period — a number, with a trigger. "7 years from last transaction," not "as needed."
- Disposal method — secure deletion, crypto-shredding, or documented anonymization. "We stop using it" is not disposal.
The retention period is where judgment lives, and where the keep-forever instinct does the most damage. Some periods are dictated for you. The Income Tax Act and CRA rules require keeping business records, including some that contain personal information, for six years from the end of the tax year they relate to. FINTRAC, under the PCMLTFA, requires reporting entities such as banks, money services businesses, real estate brokers, and dealers in precious metals to keep client identification and transaction records for five years. Employment records, provincial limitation periods for litigation, CASL consent records — each carries its own defensible minimum.
But here's the part people miss. A statutory keep-for requirement is a floor, not a ceiling, and it only applies to the specific records the statute names. CRA needing your invoices for six years does not authorize you to keep a former employee's medical accommodation file for six years, or a rejected applicant's resume for any time at all beyond the hiring decision. The agency in my opening could have set a 12-month retention on unsuccessful applicants and deleted 80% of what got breached. The cost of doing so: roughly one afternoon and a cron job.
The disposal half is the half everyone forgets
Writing the schedule is the easy part. The OPC and CAI both care intensely about whether you actually *execute* it, and whether disposal is secure. A retention schedule that no system enforces is theatre. I've reviewed plenty of well-written retention policies sitting in a SharePoint folder while the underlying databases happily retained everything from 2011.
Secure disposal means the data is genuinely unrecoverable. Dragging files to a trash icon does not count. For structured data, that means hard deletes from production and backups — with a documented, time-limited backup retention window so old data ages out of backups too — or crypto-shredding, where you destroy the encryption keys and the ciphertext becomes noise. For Quebec, anonymization is now a specific legal standard: the regulation under Law 25 requires that anonymized data be irreversibly so, assessed against the state of the art. Pseudonymization, where you can re-link with a key, is *not* anonymization and does not get you off the retention hook.
Document the disposal too. Keep a destruction log: what category, what date, what method, who authorized it. When the OPC investigates, the gap between "we believe that data was deleted" and "here is the log showing 4,200 records purged on 2026-03-31 under retention rule R-14" is the gap between a finding against you and a clean file.
Start with a data map, then set the clocks
You cannot retain-and-dispose data you don't know you have. Every defensible schedule starts with an inventory. Walk every system: the CRM, the email platform, the support desk, the HR system, that one analyst's spreadsheet, the form submissions piling up in a shared inbox, the backups, and the dev environment seeded with a copy of production. That last one is a classic, and a serious one. For each store, list the categories of personal information and where they flow.
Then set clocks against each category and pick the trigger event. Some clocks start at collection, some at last activity, some at account closure, some at the end of a contractual or statutory period. Marketing consent under CASL is a good example: tie it to engagement. An email subscriber who hasn't opened anything in three years is data you're holding without a live purpose, and arguably without valid ongoing consent.
The work is real but bounded. A small business with a dozen data categories can build a credible first schedule in a week. The reason most don't is that doing it by hand across every tool, keeping it current as new systems get bolted on, and proving enforcement is tedious and easy to let slide. That maintenance burden is exactly why retention schedules rot.
This is the part Valdra was built to take off your plate. It inventories where personal data lives, generates a category-by-category retention schedule aligned to PIPEDA, Law 25, PHIPA, and CASL, and tracks disposal so you have the destruction log when a regulator asks. If you've been meaning to fix the keep-forever problem and never found the afternoon, build your retention schedule with Valdra.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra