Most small businesses keep everything forever, not by decision but by default: old emails, spreadsheets of past customers, years of invoices, form submissions nobody looks at. It feels harmless, but every piece of personal information you hold is something you must protect and, if you are breached, something that can be stolen. A simple records-retention habit, keep what you need for as long as you need it, then delete, is one of the cheapest ways to lower your risk. This is general guidance, not legal or tax advice.
Why holding less is safer
You cannot lose what you no longer have. When attackers hit a business, the damage is measured by what they can take, and a company sitting on ten years of customer records has far more to lose than one that keeps three. Data minimisation, the principle of collecting and keeping only what you actually need, is also a core expectation of Canadian privacy law under PIPEDA and Quebec's Law 25, which specifically pushes organisations not to keep personal information past the purpose it was collected for. Less data means a smaller breach, a shorter privacy policy, lower storage cost, and less to explain if a regulator ever asks.
The two forces that set how long
Retention is a balance between two pulls. Some records you are required to keep for a set time: tax and financial records, for example, generally need to be kept for several years to satisfy the Canada Revenue Agency, and employment records have their own minimums. Other data you should delete once its purpose is done, because keeping it only adds risk: the marketing list of people who never converted, the CVs from a role you filled two years ago, the contact-form messages you already answered. The job is to sort your data into "must keep, and for how long" versus "delete when done."
A simple retention schedule
You do not need a lawyer to start. A one-page table is enough:
- List your main types of records. Financial and tax, employee records, customer and order data, marketing contacts, website form submissions, old email.
- Note why you hold each and how long. Tax records: keep per CRA guidance. Customer orders: keep while they are a customer plus a defined period. Marketing contacts: keep while they are engaged, remove on request or after inactivity. Recruitment: delete unsuccessful applicants after a set window.
- Set a delete step. The schedule only works if something actually gets deleted. Pick a recurring date, quarterly or annually, to clear what has aged out.
- Delete securely. "Delete" means gone from live systems, backups on their own cycle, and any third-party tools holding copies, not just moved to a folder.
Where it connects
Retention is one pillar of handling data responsibly, alongside knowing what you hold and being transparent about it. It fits naturally inside a light privacy management program and pairs with your privacy policy, which should reflect how long you actually keep things. Confirm the specific legal and tax minimums for your situation with a professional; the habit of not hoarding is the part you can start today.