Resources

Personal Information Retention and Destruction Policy Under Law 25

Elite Consultation·2026-06-15
Law 25retentiondestructionanonymization

Most Quebec organizations keep personal information well past the point of necessity. Employee files from the 1990s, old prospect databases that have not been used in five years, layers of customer file backups stacked without rotation: these accumulations are common and risky.

Section 23 of the Act respecting the protection of personal information in the private sector (Law 25) sets a clear obligation: once the purpose of collection has been fulfilled, personal information must be destroyed or anonymized. This obligation applies to every organization, and failure to comply is sanctionable.

This guide explains what section 23 requires, how to set defensible retention periods, the difference between destruction and anonymization, and how to build a retention policy for a Quebec SME.

What Section 23 Says

Section 23 sets out the following principle: once an organization has fulfilled the purpose for which it collected personal information, it must:

  • Destroy that information, or
  • Anonymize it, provided it follows generally accepted best practices and the criteria and modalities set by regulation.

The organization may keep the information longer when the law requires it (for example, tax records kept for six years under the Income Tax Act) or when keeping it is necessary for purposes compatible with the original collection.

The section therefore imposes three practical requirements:

  1. Define the purpose of every collection of personal information
  2. Set a reasonable retention period to fulfill that purpose
  3. Destroy or anonymize the information at the end of the period

These three steps must be documented in a retention policy.

Destruction, Anonymization, Pseudonymization: Three Distinct Mechanisms

These three terms are often confused. Under Law 25, they do not carry the same weight.

Destruction makes the information permanently inaccessible and unrecoverable. For digital files, this means secure deletion (multiple overwrite passes, physical destruction of media at end of life). For paper documents, cross-cut shredding to recognized standards.

Anonymization transforms the information so that it can no longer reasonably be associated with an identifiable person. The transformation must be irreversible. Anonymization that meets section 23 must follow recognized best practices and the criteria of the government regulation on anonymization, in force since May 2024.

Pseudonymization replaces direct identifiers (name, email, social insurance number) with codes but keeps the possibility of re-identifying the person via a lookup table. Under Law 25, pseudonymized information remains personal information and keeps all the protections that come with it.

In practice, destruction is the simplest path for most SMEs. Anonymization is technically demanding and generally costs more to validate than a clean destruction.

Building a Retention Schedule

A retention schedule is the central document. For each category of personal information, it lists:

  • The nature of the information (category)
  • The purpose of collection
  • The retention period
  • The justification for that period
  • The action at the end of the period (destruction or anonymization)
  • The person responsible for executing it

Here are the most common retention periods for a Quebec SME.

| Category | Typical period | Source | |---|---|---| | Accounting and tax records | 6 years | Income Tax Act (ITA) | | Employee files (active) | Duration of employment | Labour Code, Act respecting labour standards | | Employee files (former) | 3 to 5 years after departure | Act respecting labour standards, civil prescription | | Job applications not retained | 6 to 12 months | HR best practice, defense in case of complaint | | Payroll data | 6 years | Income Tax Act | | Prospect information (never customers) | 12 to 24 months | CRM best practice | | Active customer contact information | Duration of relationship + prescription period | Civil Code of Quebec | | Inactive customer contact information | 3 to 7 years depending on service type | Civil prescription, sectoral obligations | | Health files (clinics) | According to professional code of ethics | Professional codes | | Video surveillance | 30 to 90 days | Best practice, minimization principle | | Information system access logs | 6 to 24 months | Security, audits, minimization principle |

These periods are indicative. They should be adjusted based on sectoral obligations, applicable professional rules, and the organization's specific context.

How to Set a Defensible Retention Period

For each category, ask four questions:

  1. Does the law impose a period? Tax records (6 years), HR files (varies by context), clinical records (professional codes). Where the law sets a period, it is the minimum.
  2. Does a contractual obligation require retention? Warranties, after-sales service, service agreements that provide for historical access.
  3. What is the risk of being unable to respond to a legitimate request? Complaint, legal action, regulatory inspection.
  4. Beyond these necessities, does retention still serve a purpose? If the answer is no, the retention is no longer justified and must end.

The honest answer to the fourth question dictates the maximum period. Keeping data "just in case" is not a valid purpose under Law 25.

Execution: Automate Whenever Possible

The best retention policy is useless if destruction never actually happens. Three complementary approaches work:

Technical automation. Configure tools (CRM, document management, email, backups) to automatically purge records after the retention period. Most modern platforms offer these functions, but they are almost never enabled by default.

Periodic manual review. For categories that do not lend themselves to automation, schedule an annual or semi-annual review. The privacy officer should be able to confirm each year that the review has been done.

Documented destruction. Each destruction (paper or digital) should leave a record: date, category, volume, method, person responsible. This traceability is essential during a complaint or audit.

Common Mistakes

  • Keeping data "just in case" with no real purpose. This practice is explicitly non-compliant with Law 25.
  • Confusing archiving with retention for active purposes. A dormant archive that is never consulted does not qualify as retention for compatible purposes.
  • Forgetting backups. Destroying active records without purging backups leaves the information accessible. The retention policy must cover backups.
  • Thinking anonymization is quick. Compliant anonymization requires rigorous analysis of the re-identification risk. For most SMEs, destruction is simpler and less risky.
  • Confusing anonymization with pseudonymization. Pseudonymized information remains subject to Law 25.

How Observantia Supports This Work

Observantia centralizes the retention schedule, flags the information due for destruction, and keeps the documentation of completed destructions. The dashboard helps the privacy officer demonstrate the organization's diligence during an inspection or complaint. Start your 14-day free trial.

Related articles


This content is provided for informational purposes only and does not constitute legal advice. For questions specific to your situation, consult a qualified legal professional.

Ready to simplify your compliance?

Try Observantia free for 14 days.