✉️ MapleMail
Legal & compliance

How long do you have to keep business emails in Canada?

There is no "email retention law" in Canada. There is a records-retention law, and email is one of the places records happen to live. That distinction answers almost every version of this question.

The short answer

Canadian law sets no retention period for email. It sets periods for records, and an email is a record when it documents something - a sale, an agreement, a price. Those inherit the general six-year tax rule. Email that documents nothing carries no duty, and privacy law says personal information should not be kept indefinitely.

Ask ten small business owners how long they keep business email and you get two answers. Most say "forever, it is all in there somewhere". A few say "I clear it out when the mailbox gets full". Both are answering a question the law does not ask.

No Canadian statute has a section about email. What the statutes have is a duty to keep records, and email is simply one of the places records now live - alongside your accounting software, your filing cabinet and your phone. Once you see it that way, the question stops being "how long do I keep email" and becomes "what is in this message, and does that thing have a retention period". That is a much easier question to answer.

Email is a container, not a category

Start with the definition. The Income Tax Act defines a record to include an account, an agreement, a book, a chart or table, a diagram, a form, an image, an invoice, a letter, a map, a memorandum, a plan, a return, a statement, a telegram, a voucher, and any other thing containing information, whether in writing or in any other form [1]. Read that list again. A letter. A memorandum. An invoice. Any other thing containing information, in any form.

Nothing in there is about paper. An emailed invoice is an invoice. An email confirming the scope and price of a job is an agreement. A message where you tell a customer their deposit was received is a statement. Those are records in the ordinary legal sense, and the fact that they arrived through a mail server rather than an envelope changes nothing about their status.

Equally, most of a normal mailbox is not a record of anything. A quote that went nowhere, a scheduling back-and-forth, a supplier newsletter, an internal "can you cover Thursday" - these document no transaction and support no figure on a return. There is no legal obligation to keep them. Whether you do is an operational preference, not a compliance decision.

The statutory duty, in plain terms

Every person carrying on business, and every person required to pay or collect tax, must keep records and books of account in such form and containing such information as will enable the taxes payable to be determined [1]. That is the core obligation. It is outcome-based: the test is whether your records let the amount be worked out, not whether you filed them in a particular way.

On timing, the general rule is that records must be retained, together with every account and voucher necessary to verify the information in them, until six years from the end of the last taxation year to which the records relate [1]. Note the phrasing - the last taxation year to which the records relate, not the date the document was created. A supply agreement signed in 2024 that governs invoicing through 2027 relates to 2027, so its clock runs from the end of that year, not from the day it was signed.

The GST/HST side works the same way. Under the Excise Tax Act, every person who carries on a business or is engaged in a commercial activity in Canada, files a return under that Part, or applies for a rebate or refund, must keep all records necessary to enable the determination of their liabilities and obligations [3]. Those records must be retained until six years after the end of the year to which they relate [3]. That Act also says that unless the Minister authorizes otherwise, records are to be kept in Canada in English or in French [3] - a detail worth knowing if you are deciding where your business mail is stored.

Four things that extend the clock

The six-year figure gets quoted as if it were the whole rule. It is the default, and several provisions override it.

  • An unfiled return. Where a return for a taxation year was not filed as and when required, the records relating to that year must be kept until six years from the day the return is actually filed [1]. Skipping a filing does not shorten your obligation - it suspends the start of it.
  • An objection or appeal. If you serve a notice of objection or become a party to an appeal to the Tax Court, you must retain every record, book of account, account and voucher necessary for dealing with it until the time to appeal has elapsed or the appeal and any further appeal are disposed of [1]. The Excise Tax Act imposes the same duty for GST/HST objections, appeals and references [3].
  • A written demand. Where the Minister considers it necessary for administering the Act, a demand can be served by registered letter or personally requiring records to be retained for a specified period [1]. The Excise Tax Act contains a matching power [3].
  • Certain corporate records. The Income Tax Regulations prescribe separate periods: minutes of directors' and shareholders' meetings, records of share ownership and transfers, the general ledger or other book of final entry, and special contracts or agreements necessary to understand entries in it, are kept until two years after the corporation is dissolved [2]. For a corporation that is still operating, that means indefinitely.

There is a release valve in the other direction too. Both Acts let you dispose of records before the end of the period if the Minister gives written permission [1][3]. That is a formal process, not a judgment call you make yourself.

"Electronically readable" is a real requirement

This one gets missed. Where a person required to keep records does so electronically, they must retain them in an electronically readable format for the retention period [1]. The Excise Tax Act says the same [3]. Both Acts allow the Minister to exempt a person or class of persons from that requirement on acceptable terms [1][3], but you should not plan around an exemption you have not asked for.

The practical consequence is that "I have a backup somewhere" is not automatically compliance. If your archive is a proprietary export from mail software you stopped paying for, or an encrypted disk whose password left with a former bookkeeper, or a format nothing you own can open, you are holding data but not a readable record. Anything portable - standard mailbox exports, PDFs, plain files - stays readable for the length of a six-year window. Anything vendor-locked might not.

The other direction: privacy law says stop hoarding

Here is what makes this question genuinely two-sided rather than "keep everything, be safe". PIPEDA applies to every organization in respect of personal information it collects, uses or discloses in the course of commercial activities [5]. Personal information means information about an identifiable individual [5], and the Act's own definition of record includes correspondence and memoranda regardless of physical form, plus any copy of them [5]. Customer email is squarely inside all three definitions.

Principle 5 of Schedule 1 then states that personal information shall be retained only as long as necessary for the fulfilment of the purposes for which it was collected [4]. The guidance under it goes further: organizations should develop retention guidelines including minimum and maximum periods, and personal information no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous [4]. The same clause acknowledges that an organization may be subject to legislative requirements on retention periods [4] - which is exactly how the tax rules and the privacy rules coexist: keep what the law requires, for as long as it requires, and let the rest go.

So indefinite retention of everything is not the safe default it looks like. A ten-year-old mailbox full of customer addresses, phone numbers, health-related notes and payment discussions is personal information being held past its purpose - and it is also the blast radius of any future incident. On that point, note that PIPEDA requires an organization to keep and maintain a record of every breach of security safeguards involving personal information under its control [5], and the regulations set that record-keeping period at 24 months after the day the organization determines the breach occurred [6]. More retained mail means a bigger breach to record, disclose and explain.

The honest concession

Now the part most compliance writing leaves out. For a typical small business, mailbox storage is cheap and sorting old mail is expensive. An owner who spends six hours a year triaging correspondence to delete messages that cost a few dollars to store is losing money on the exercise. Broad retention is often the reasonable practical answer, and pretending otherwise makes for tidy advice and bad economics.

The real discipline is not aggressive deletion. It is two narrower habits:

  • Know what you cannot delete. The transaction trail, the agreements, the objection-related correspondence, the corporate records under Regulation 5800 [2]. These need to survive a mailbox migration, a laptop failure and a staff departure - which means they should not exist only inside one person's inbox.
  • Know what you should not be hoarding. Bulk personal information with no live purpose: old applicant resumes, a decade of customer identity documents someone emailed in, health or financial details captured for a job that closed years ago. That material is the part where "keep everything" turns into a liability rather than an insurance policy.

Everything between those two poles - ordinary work correspondence with no personal-information payload and no evidentiary role - can be kept broadly without much thought. That is the honest shape of the problem.

A note on precision

The retention periods above come from the statutes and regulations themselves, and they are written in general terms because the Acts apply to everyone from a sole proprietor to a bank. Your own situation may involve provincial statutes, industry regulators, employment records or professional obligations with their own periods, and tax administration publishes its own guidance on how the general rules apply in specific cases. Treat this article as the shape of the rules, and confirm the exact obligations for your business and your year-ends with the tax administration or your accountant before you destroy anything.

Do this this week

Pick one thing: find the last three transactions your business completed and check whether the documenting email exists anywhere other than one person's inbox. If the answer is no, that is your actual retention risk - not the length of the period, but the single point of failure holding the record. Export those threads, or the attachments, into whatever folder your bookkeeping already lives in. Then write down, in three lines, which categories of mail your business must keep and which contain customer personal information. That short list is a retention policy, and it is more than most small businesses have.

Frequently asked questions

How long do I have to keep business emails in Canada?

There is no retention period for "email" as such. The Income Tax Act sets the general rule at six years from the end of the last taxation year the records relate to, and that duty attaches to records - which are defined broadly enough to include a letter or memorandum in any form. So an email that documents a transaction inherits the six-year clock; an email that documents nothing inherits no clock at all.

Is an email legally a business record?

It can be. The Income Tax Act defines a record to include an account, an agreement, a book, a form, an image, an invoice, a letter, a memorandum, a statement, a voucher and any other thing containing information, whether in writing or in any other form. Nothing in that list is about paper. An emailed invoice or a written agreement to a price is a record; a note asking a colleague to pick up coffee is not.

Does the six-year clock start from the date of the email?

No, and this trips people up. Under the Income Tax Act the period generally runs until six years from the end of the last taxation year to which the records relate, not six years from when the document was created. A contract signed in one year that governs revenue for the next three relates to all of those years, so its clock ends later than its date suggests.

What if I never filed a return for that year?

The clock does not start. The Income Tax Act says that where a person has not filed a return for a taxation year as and when required, they must retain the records relating to that year until six years from the day the return is actually filed. An unfiled year is an open-ended retention obligation, not a shorter one.

Can I delete emails while a CRA dispute is open?

No. Where a person serves a notice of objection or is a party to an appeal, the Income Tax Act requires retention of every record, book, account and voucher necessary for dealing with the objection or appeal until the appeal period has elapsed or the appeal is finally disposed of. The Excise Tax Act carries a parallel rule for GST/HST. The Minister can also serve a written demand requiring records to be kept for a specified period.

Do electronic records have to be kept in a special format?

They have to stay readable. A person required to keep records who keeps them electronically must retain them in an electronically readable format for the whole retention period - this appears in both the Income Tax Act and the Excise Tax Act. A backup nobody can open, or an export in a format your software no longer reads, is not a satisfied obligation.

Does keeping everything forever protect me?

Not entirely, and it creates a second problem. PIPEDA Schedule 1 says personal information shall be retained only as long as necessary for the fulfilment of the identified purposes, and that information no longer required should be destroyed, erased, or made anonymous. Indefinite retention of mail containing customer personal information sits against that principle, and it enlarges the pile exposed by any future breach.

Are there records I have to keep longer than six years?

Yes. The Income Tax Regulations prescribe separate periods for certain corporate records - director and shareholder minutes, the share ownership register, the general ledger or other book of final entry, and special agreements needed to understand its entries - which run until two years after the day the corporation is dissolved. For a live corporation, that is effectively permanent.

How long do I keep a record of a privacy breach?

Twenty-four months. PIPEDA requires an organization to keep and maintain a record of every breach of security safeguards involving personal information under its control, and the Breach of Security Safeguards Regulations set that record-keeping period at 24 months after the day the organization determines the breach occurred. The email thread where you worked out what happened is often that record.

Sources

  1. Income Tax Act (full text) — R.S.C. 1985, c. 1 (5th Supp.) - s. 230(1), (4), (4.1), (5), (6), (7), (8); "record" defined in s. 248(1)
  2. Income Tax Regulations, C.R.C., c. 945 — Part LVIII, s. 5800 - prescribed retention periods for minute books, share registers and general ledgers
  3. Excise Tax Act (full text) — R.S.C. 1985, c. E-15 - s. 286(1), (1.2), (3), (3.1), (4), (5), (6) (GST/HST books and records)
  4. PIPEDA - Schedule 1, Principle 5 (Limiting Use, Disclosure, and Retention) — Clauses 4.5, 4.5.2, 4.5.3 - retain only as long as necessary; destroy, erase or make anonymous
  5. Personal Information Protection and Electronic Documents Act (full text) — S.C. 2000, c. 5 - s. 2(1) "record" and "personal information", s. 4(1) application, s. 10.3 breach records
  6. Breach of Security Safeguards Regulations, SOR/2018-64 — s. 6(1) - keep a record of every breach for 24 months after the day the organization determines it occurred

All sources verified 2026-08-28.

Business email on your own domain

See MapleMail pricing