Compliance

Document retention under Law 25: the durations are not in the law

July 31, 2026
Xavier PeichBy Xavier Peich

Law 25 sets no retention periods. It requires destruction or anonymization once the purpose is fulfilled. The real minimums come from other laws.

Document retention under Law 25: the durations are not in the law

Search for "Law 25 document retention periods" and you will find confident tables: three years for this, seven years for that. The problem is that Law 25 contains no durations. Not one. If you have read our summary of Law 25 obligations for SMBs, you know the law reasons differently: it does not tell you how long to keep your documents, it tells you when you no longer have the right to keep them.

That is a complete reversal of the question most business owners ask. And it changes the nature of the risk: for decades, the prudent reflex was to keep everything, just in case. Under Law 25, that reflex is now a potential violation.

This article explains what the law actually requires, where the real minimum durations come from, and what a reasonable retention policy looks like for a Quebec SMB.

The short answer, for the busy

Law 25 sets no retention periods for documents. Section 23 of Quebec's Act respecting the protection of personal information in the private sector imposes an end-of-life rule instead: once the purposes for which personal information was collected or used are fulfilled, the business must destroy it or anonymize it, subject to any retention period set by another law. The minimum durations therefore come from elsewhere: accounting records and supporting documents must be kept for six years from the end of the last tax year they relate to, a requirement of both the Canada Revenue Agency and Revenu Québec that also covers payroll records. For everything else, rejected candidates' resumes, mailing lists, dormant client files, the right question is not "how long am I allowed to keep this?" but "is the purpose fulfilled?". If it is, continued retention is itself a violation.

What section 23 actually requires

The rule fits in one sentence: once the purposes for which personal information was collected or used are fulfilled, the business must destroy it, or anonymize it in order to use it for serious and legitimate purposes, subject to any retention period provided by law.

Three things to notice. First, the trigger is the fulfillment of the purpose, not a calendar date. A client's file serves a purpose as long as the relationship lasts; an application serves a purpose until the position is filled. After that, the countdown is over.

Second, there are two exits, not one. Destroy, or anonymize in order to use the information for serious and legitimate purposes, internal statistics for instance. But beware: anonymized, in the legal sense, means it is no longer reasonable to expect the information could identify the person, directly or indirectly, and irreversibly so. A regulation has governed the process since May 2024: supervision by a qualified person, a re-identification risk assessment, a registry of anonymized information. Stripping the names out of a spreadsheet is not anonymization. For most SMBs, the realistic exit is destruction.

Third, the carve-out: "subject to a retention period provided by law". That is the door the real durations come through.

The minimums come from tax law, not Law 25

The duration everyone is looking for exists, just somewhere else. The Canada Revenue Agency requires that books, records, and supporting documents be kept for six years from the end of the last tax year they relate to. Similar rules apply under the Income Tax Act, the Excise Tax Act (so GST/HST), the Employment Insurance Act, and the Canada Pension Plan, which covers your payroll files. Revenu Québec imposes the same six years on its side. One detail that catches people: if you file a return late, the six years run from the filing date, not the year end. And some documents are kept indefinitely, such as the share registry and records tied to long-term property.

The practical consequence: a client's invoice, the contract, the pay slip, everything supporting your tax filings is kept six years, and section 23 explicitly allows it. But the tax minimum protects the tax document, not the rest of the file. The chat history with that client, their preferences noted in the CRM, the emails exchanged: none of that is an accounting record. Invoking "taxes" to keep everything is exactly the shortcut the law no longer permits.

The textbook case: rejected candidates' resumes

This is where the gap between common practice and the rule is widest. Almost every business keeps the applications it receives, indefinitely, "in case a position opens up". Quebec's privacy regulator, the Commission d'accès à l'information, which published hiring guidelines in 2025, is clear: once the hiring process ends, the purpose is fulfilled, and unsuccessful candidates' information must be securely destroyed. Keeping it for future openings is a secondary use, which requires the person's consent.

The clean solution is simple: ask for consent at application time. A checkbox, "I agree that my application may be kept for twelve months for other positions", settles the matter. Without that consent, the resume bank your company has been building for years stops being an asset and becomes a stockpile of information held without a right to it. If you believe you have a serious reason to keep a specific application file longer, document it with your privacy officer: that is exactly the kind of call the role exists for.

An SMB's retention matrix, told rather than tabulated

Client files: while the relationship is active, the purpose runs. When it ends, separate what supports your accounting (contracts, invoices: six years) from what does not (correspondence, notes, preferences: destruction within a reasonable delay once mutual obligations are extinguished).

Mailing lists and newsletters: the purpose is sending communications the person consented to. An unsubscribe ends that purpose. You may keep the strict minimum needed to honour the unsubscribe itself, a suppression list, but not the person's full profile.

Website forms: every form should have a declared purpose and a planned end of life. A quote request that went nowhere two years ago no longer has one. Your privacy policy should say what you do with this data, and your practice should match it.

Backups: the classic blind spot. Destroying information in the production system does not destroy its backup copies. The defensible approach is rotation with a defined lifespan: backups expire after a documented period, so deleted data eventually disappears everywhere. Document that period, and never restore destroyed personal information back into circulation.

Keeping everything "just in case" became a liability

The keep-everything reflex dates from an era when a document's only cost was filing-cabinet space. That math has changed twice. First, every retained record is breach surface: if your systems are compromised, the scope of what you must assess, log in your confidentiality incident registry, and potentially report depends directly on what you were holding. Ten years of resumes and dead client files turn a minor incident into a major operation.

Second, wrongful retention is punishable in itself. Section 91 of the Act expressly targets anyone who "keeps" personal information in contravention of the law, with penal fines of up to $25 million or 4% of worldwide turnover, and administrative penalties of up to $10 million or 2%. Nobody will hit an SMB with the maximum over old resumes. But the legislator's message is unambiguous: data you no longer hold cannot leak, cannot be demanded, and cannot be held against you.

Where to start

Law 25 already requires your governance policies to cover the retention and destruction of personal information, with the essentials published on your website. The realistic path takes three moves: inventory where personal information lives (CRM, email, forms, backups), write one page mapping each category to its purpose and its end-of-life rule, then automate what can be automated, starting with purging old form submissions.

This is work we build into the ongoing management of our clients' sites: a well-kept site is also one that is not storing ten years of forgotten form entries. If you want to talk it through, the first conversation costs nothing.

→ Tell us about your situation

This article explains legal obligations to help an SMB ask the right questions; it is not legal advice. Tax retention periods have exceptions and the exact scope of your obligations depends on your situation: validate your retention rules with a legal or accounting advisor. The official texts (P-39.1, tax statutes) prevail.

Xavier Peich

Written by

Xavier Peich

Document retention under Law 25: the durations are not in the law | Blog PEICH | PEICH