1. Purpose and Scope
This policy aims to govern the retention and destruction of the company's clients' personal information, in compliance with the obligations arising from Law 25 (Act to modernize legislative provisions as regards the protection of personal information, Quebec) and the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada).
It aims to ensure that personal information is retained only for as long as strictly necessary for the purposes for which it was collected, and that it is securely destroyed once its retention period has expired.
Scope: This policy applies to:
All employees of the company, regardless of their role;
All subcontractors and service providers with access to client data;
All IT systems and platforms processing client data (online buyers, prospects, newsletter subscribers).
Main legal references: Law 25 (Quebec) • PIPEDA (Canada) • Civil Code of Québec • Tax Administration Act (Quebec)
2. Key Definitions
Term | Definition |
|---|---|
Personal information | Any information concerning a natural person that allows them to be identified, directly or indirectly (e.g., name, email address, purchase history, IP address). |
Destruction | The permanent and irrecoverable elimination of personal information, by technical or physical means (secure deletion, shredding, cryptographic erasure). |
Anonymization | An irreversible process by which personal information is modified so that it can no longer be used to identify a person, directly or indirectly, by any means whatsoever. |
Person in Charge of the Protection of Personal Information (PCPPI) | Person appointed within the company to oversee the application of Law 25, handle client rights requests, and report incidents to the Commission d'accès à l'information (CAI). |
Confidentiality incident | Any unauthorized access, use, disclosure, modification, or loss of personal information, whether accidental or malicious. |
Inactive file | Client file for which no interaction or transaction has been recorded for a set period (generally 12 consecutive months), with no active business relationship. |
3. Fundamental Principles – Law 25
The company adheres to the following five guiding principles, as set out in Law 25:
Minimization: Collect only the personal information strictly necessary for the expressly determined purposes. Excessive collection is prohibited.
Purpose limitation: Use personal information only for the purposes for which it was collected and for which consent was obtained.
Limited duration: Retain personal information only for as long as necessary to achieve the purposes for which it was collected, in accordance with applicable legal deadlines.
Adequate protection: Implement physical, technical, and administrative security measures proportionate to the sensitivity of the information held.
Secure destruction: Securely destroy or anonymize any personal information whose retention period has expired, according to the procedures described in section 7 of this policy.
4. Retention Period Table
The following table constitutes the company's official personal information retention schedule. It must be applied systematically by the IT, commercial, and customer service teams.
Data type | Retention period | Legal basis | Trigger |
|---|---|---|---|
Active client account data (name, email, preferences) | Duration of business relationship + 3 years | Law 25 • Civil Code of Québec (art. 2925) | Account closure or deactivation |
Order and invoice history | 7 years | Quebec Tax Administration Act • Income Tax Act (Canada) | Transaction date |
Payment data – full card number | NOT RETAINED | Law 25 • PCI-DSS standard | Immediate deletion after transaction processing |
Payment confirmations and receipts (partial data) | 7 years | Quebec and federal tax law | Transaction date |
Shipping addresses | 7 years | Tax law • Dispute management (Civil Code) | Date of the last related order |
Browsing data and cookies | 13 months maximum | Law 25 • CAI guidelines | Collection date (renewed upon consent) |
Login and security logs | 12 months | IT security • Law 25 (art. 85) | Log creation date |
Proof of marketing consent | 3 years after consent withdrawal | Law 25 • PIPEDA | Date of withdrawal or expiration of consent |
Customer service requests (tickets, exchanges) | 3 years | Civil Code of Québec (prescriptive period, art. 2925) | File closure date |
Unconverted prospects (forms, newsletters) | 3 years since last contact | Law 25 • Minimization principle | Date of last contact or interaction |
Dispute or claim data | Duration of dispute + 3 years | Civil Code of Québec (art. 2925) | Final resolution date of the dispute |
5. Responsibilities
The management of personal information is a shared responsibility within the organization, allocated as follows:
Who | Role | Main responsibility |
|---|---|---|
Person in Charge of the Protection of Personal Information (PCPPI) | Law 25 compliance | Oversee the application of the policy; handle client rights requests; report incidents to the CAI; maintain the mandatory registers; train staff. |
Senior Management | Governance | Approve and review the policy; allocate the resources necessary for compliance; appoint the PCPPI. |
IT / Systems Team | Technical implementation | Implement automated destruction procedures; secure systems; verify backups; log access; delete data in third-party systems. |
All employees | Individual compliance | Comply with this policy in the performance of their duties; immediately report any incident or irregularity to the PCPPI; do not retain unauthorized copies. |
6. Security Measures
The company implements the following security measures, proportionate to the sensitivity of the personal information processed:
Data encryption: AES-256 for data at rest; TLS 1.2 or higher protocol for data in transit over networks.
Access based on the principle of least privilege: Each employee or system only has access to the information necessary to perform their specific duties.
Two-factor authentication (2FA): Mandatory for any access to systems containing clients' personal information.
Annual access review: Formal and documented verification of all data access rights, performed each year by the IT team.
Confidentiality agreements with subcontractors: Any supplier or subcontractor processing data on the company's behalf must sign a confidentiality and processing agreement compliant with Law 25.
Logging of sensitive access: All access to sensitive client data is recorded in an audit log, retained for 12 months.
7. Secure Destruction Procedures
As soon as the applicable retention period expires, personal information must be destroyed or irreversibly anonymized, according to the procedures below.
7.1 Digital Data
Secure deletion: Use of a multi-pass overwrite method or cryptographic erasure (destruction of the encryption key) rendering the data unrecoverable.
Physical destruction of media: When decommissioning hard drives or storage media, certified physical destruction (shredding or grinding to an adequate level).
Verification in backups and third-party systems: Ensure that data to be destroyed is also removed from automatic backups, cloud hosting environments, and third-party provider systems.
Mandatory logging: Every destruction operation must be documented in the Destruction Register (date, type of data, system concerned, person responsible for the operation).
7.2 Paper Documents
Secure shredding: Any paper document containing personal information must be shredded to a minimum level of P-4 in accordance with DIN 66399 (particles of 160 mm² or less).
NAID-certified provider: For highly sensitive documents, mandatory use of a NAID AAA-certified destruction provider, with a certificate of destruction provided to the company and kept in the Destruction Register.
8. Client Rights
In accordance with Law 25, any client whose personal information is held by the company has the following rights:
Right | Description | Response time |
|---|---|---|
Right of access | Obtain communication of the personal information held about them and information on its use. | 30 days |
Right of rectification | Have any inaccurate, incomplete, or ambiguous personal information corrected. | 30 days |
Withdrawal of consent | Withdraw, at any time, their consent to the collection, use, or disclosure of their information. | Immediate effect |
Right to erasure | Request the deletion of their personal information (subject to legal retention obligations). | 30 days |
Right to portability | Receive their computerized personal information in a structured, commonly used technological format. | 30 days |
9. Confidentiality Incident Management
A confidentiality incident refers to any unauthorized access, use, disclosure, modification, or loss of personal information, whether intentional or accidental. The company is committed to handling any incident diligently and transparently, in accordance with sections 3.5 and following of Law 25.
Procedure to follow in the event of an incident:
Detect and contain the incident immediately upon discovery; isolate compromised systems if necessary.
Assess the risk of serious harm to the persons concerned, in collaboration with the PCPPI and the IT team.
Notify the Commission d'accès à l'information (CAI) within 72 hours if the incident presents a risk of serious harm.
Notify the persons concerned without undue delay as soon as a risk of serious harm is confirmed, with the information necessary for them to protect themselves.
Record the incident in the Confidentiality Incident Register, including the nature of the incident, the data affected, the measures taken, and the timelines.
Implement corrective measures to prevent the incident from recurring and to strengthen security controls.
10. Sanctions and Non-Compliance
Failure to comply with the obligations set out in Law 25 may expose the company to administrative monetary penalties of up to $25,000,000 or 4% of worldwide turnover for the previous fiscal year, whichever is greater, imposed by the Commission d'accès à l'information du Québec.
Internally, any breach of this policy by an employee may result in disciplinary measures, up to and including termination of employment depending on the severity of the facts, in accordance with the company's disciplinary policies and applicable agreements. Any breach must be reported to the PCPPI and to Senior Management.
11. Effective Date and Review
Effective date | July 15, 2026 |
|---|---|
Next mandatory review | July 2027 |
Person responsible for the review | Person in Charge of the Protection of Personal Information (PCPPI) |
Approval of amendments | Senior Management – mandatory communication to all staff |
This policy shall be reviewed annually, or at any time in the event of a legislative amendment, a significant organizational change, or following a major confidentiality incident. Any revised version fully replaces the previous version upon its approval.