1. Purpose and Scope

This policy aims to govern the retention and destruction of the company's clients' personal information, in compliance with the obligations arising from Law 25 (Act to modernize legislative provisions as regards the protection of personal information, Quebec) and the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada).

It aims to ensure that personal information is retained only for as long as strictly necessary for the purposes for which it was collected, and that it is securely destroyed once its retention period has expired.

Scope: This policy applies to:

  • All employees of the company, regardless of their role;

  • All subcontractors and service providers with access to client data;

  • All IT systems and platforms processing client data (online buyers, prospects, newsletter subscribers).

Main legal references: Law 25 (Quebec) • PIPEDA (Canada) • Civil Code of Québec • Tax Administration Act (Quebec)

2. Key Definitions

Term

Definition

Personal information

Any information concerning a natural person that allows them to be identified, directly or indirectly (e.g., name, email address, purchase history, IP address).

Destruction

The permanent and irrecoverable elimination of personal information, by technical or physical means (secure deletion, shredding, cryptographic erasure).

Anonymization

An irreversible process by which personal information is modified so that it can no longer be used to identify a person, directly or indirectly, by any means whatsoever.

Person in Charge of the Protection of Personal Information (PCPPI)

Person appointed within the company to oversee the application of Law 25, handle client rights requests, and report incidents to the Commission d'accès à l'information (CAI).

Confidentiality incident

Any unauthorized access, use, disclosure, modification, or loss of personal information, whether accidental or malicious.

Inactive file

Client file for which no interaction or transaction has been recorded for a set period (generally 12 consecutive months), with no active business relationship.

 

3. Fundamental Principles – Law 25

The company adheres to the following five guiding principles, as set out in Law 25:

  1. Minimization: Collect only the personal information strictly necessary for the expressly determined purposes. Excessive collection is prohibited.

  2. Purpose limitation: Use personal information only for the purposes for which it was collected and for which consent was obtained.

  3. Limited duration: Retain personal information only for as long as necessary to achieve the purposes for which it was collected, in accordance with applicable legal deadlines.

  4. Adequate protection: Implement physical, technical, and administrative security measures proportionate to the sensitivity of the information held.

  5. Secure destruction: Securely destroy or anonymize any personal information whose retention period has expired, according to the procedures described in section 7 of this policy.

4. Retention Period Table

The following table constitutes the company's official personal information retention schedule. It must be applied systematically by the IT, commercial, and customer service teams.

Data type

Retention period

Legal basis

Trigger

Active client account data (name, email, preferences)

Duration of business relationship + 3 years

Law 25 • Civil Code of Québec (art. 2925)

Account closure or deactivation

Order and invoice history

7 years

Quebec Tax Administration Act • Income Tax Act (Canada)

Transaction date

Payment data – full card number

NOT RETAINED

Law 25 • PCI-DSS standard

Immediate deletion after transaction processing

Payment confirmations and receipts (partial data)

7 years

Quebec and federal tax law

Transaction date

Shipping addresses

7 years

Tax law • Dispute management (Civil Code)

Date of the last related order

Browsing data and cookies

13 months maximum

Law 25 • CAI guidelines

Collection date (renewed upon consent)

Login and security logs

12 months

IT security • Law 25 (art. 85)

Log creation date

Proof of marketing consent

3 years after consent withdrawal

Law 25 • PIPEDA

Date of withdrawal or expiration of consent

Customer service requests (tickets, exchanges)

3 years

Civil Code of Québec (prescriptive period, art. 2925)

File closure date

Unconverted prospects (forms, newsletters)

3 years since last contact

Law 25 • Minimization principle

Date of last contact or interaction

Dispute or claim data

Duration of dispute + 3 years

Civil Code of Québec (art. 2925)

Final resolution date of the dispute

5. Responsibilities

The management of personal information is a shared responsibility within the organization, allocated as follows:

Who

Role

Main responsibility

Person in Charge of the Protection of Personal Information (PCPPI)

Law 25 compliance

Oversee the application of the policy; handle client rights requests; report incidents to the CAI; maintain the mandatory registers; train staff.

Senior Management

Governance

Approve and review the policy; allocate the resources necessary for compliance; appoint the PCPPI.

IT / Systems Team

Technical implementation

Implement automated destruction procedures; secure systems; verify backups; log access; delete data in third-party systems.

All employees

Individual compliance

Comply with this policy in the performance of their duties; immediately report any incident or irregularity to the PCPPI; do not retain unauthorized copies.

 

6. Security Measures

The company implements the following security measures, proportionate to the sensitivity of the personal information processed:

  • Data encryption: AES-256 for data at rest; TLS 1.2 or higher protocol for data in transit over networks.

  • Access based on the principle of least privilege: Each employee or system only has access to the information necessary to perform their specific duties.

  • Two-factor authentication (2FA): Mandatory for any access to systems containing clients' personal information.

  • Annual access review: Formal and documented verification of all data access rights, performed each year by the IT team.

  • Confidentiality agreements with subcontractors: Any supplier or subcontractor processing data on the company's behalf must sign a confidentiality and processing agreement compliant with Law 25.

  • Logging of sensitive access: All access to sensitive client data is recorded in an audit log, retained for 12 months.

7. Secure Destruction Procedures

As soon as the applicable retention period expires, personal information must be destroyed or irreversibly anonymized, according to the procedures below.

7.1 Digital Data

  • Secure deletion: Use of a multi-pass overwrite method or cryptographic erasure (destruction of the encryption key) rendering the data unrecoverable.

  • Physical destruction of media: When decommissioning hard drives or storage media, certified physical destruction (shredding or grinding to an adequate level).

  • Verification in backups and third-party systems: Ensure that data to be destroyed is also removed from automatic backups, cloud hosting environments, and third-party provider systems.

  • Mandatory logging: Every destruction operation must be documented in the Destruction Register (date, type of data, system concerned, person responsible for the operation).

7.2 Paper Documents

  • Secure shredding: Any paper document containing personal information must be shredded to a minimum level of P-4 in accordance with DIN 66399 (particles of 160 mm² or less).

  • NAID-certified provider: For highly sensitive documents, mandatory use of a NAID AAA-certified destruction provider, with a certificate of destruction provided to the company and kept in the Destruction Register.

8. Client Rights

In accordance with Law 25, any client whose personal information is held by the company has the following rights:

Right

Description

Response time

Right of access

Obtain communication of the personal information held about them and information on its use.

30 days

Right of rectification

Have any inaccurate, incomplete, or ambiguous personal information corrected.

30 days

Withdrawal of consent

Withdraw, at any time, their consent to the collection, use, or disclosure of their information.

Immediate effect

Right to erasure

Request the deletion of their personal information (subject to legal retention obligations).

30 days

Right to portability

Receive their computerized personal information in a structured, commonly used technological format.

30 days

 

9. Confidentiality Incident Management

A confidentiality incident refers to any unauthorized access, use, disclosure, modification, or loss of personal information, whether intentional or accidental. The company is committed to handling any incident diligently and transparently, in accordance with sections 3.5 and following of Law 25.

Procedure to follow in the event of an incident:

  1. Detect and contain the incident immediately upon discovery; isolate compromised systems if necessary.

  2. Assess the risk of serious harm to the persons concerned, in collaboration with the PCPPI and the IT team.

  3. Notify the Commission d'accès à l'information (CAI) within 72 hours if the incident presents a risk of serious harm.

  4. Notify the persons concerned without undue delay as soon as a risk of serious harm is confirmed, with the information necessary for them to protect themselves.

  5. Record the incident in the Confidentiality Incident Register, including the nature of the incident, the data affected, the measures taken, and the timelines.

  6. Implement corrective measures to prevent the incident from recurring and to strengthen security controls.

10. Sanctions and Non-Compliance

Failure to comply with the obligations set out in Law 25 may expose the company to administrative monetary penalties of up to $25,000,000 or 4% of worldwide turnover for the previous fiscal year, whichever is greater, imposed by the Commission d'accès à l'information du Québec.

Internally, any breach of this policy by an employee may result in disciplinary measures, up to and including termination of employment depending on the severity of the facts, in accordance with the company's disciplinary policies and applicable agreements. Any breach must be reported to the PCPPI and to Senior Management.

11. Effective Date and Review

Effective date

July 15, 2026

Next mandatory review

July 2027

Person responsible for the review

Person in Charge of the Protection of Personal Information (PCPPI)

Approval of amendments

Senior Management – mandatory communication to all staff

This policy shall be reviewed annually, or at any time in the event of a legislative amendment, a significant organizational change, or following a major confidentiality incident. Any revised version fully replaces the previous version upon its approval.

Quality you can count on

Introduce your customers to local products renowned for their quality and authenticity. Since 1937, Labonté Honey has been supporting foodservice and hospitality professionals with products recognized for their quality, consistency, and authenticity.

Contact us today