The short answer
Canadian law sets no retention period for email. It sets periods for records, and an email is a record when it documents something - a sale, an agreement, a price. Those inherit the general six-year tax rule. Email that documents nothing carries no duty, and privacy law says personal information should not be kept indefinitely.
Ask ten small business owners how long they keep business email and you get two answers. Most say "forever, it is all in there somewhere". A few say "I clear it out when the mailbox gets full". Both are answering a question the law does not ask.
No Canadian statute has a section about email. What the statutes have is a duty to keep records, and email is simply one of the places records now live - alongside your accounting software, your filing cabinet and your phone. Once you see it that way, the question stops being "how long do I keep email" and becomes "what is in this message, and does that thing have a retention period". That is a much easier question to answer.
Email is a container, not a category
Start with the definition. The Income Tax Act defines a record to include an account, an agreement, a book, a chart or table, a diagram, a form, an image, an invoice, a letter, a map, a memorandum, a plan, a return, a statement, a telegram, a voucher, and any other thing containing information, whether in writing or in any other form [1]. Read that list again. A letter. A memorandum. An invoice. Any other thing containing information, in any form.
Nothing in there is about paper. An emailed invoice is an invoice. An email confirming the scope and price of a job is an agreement. A message where you tell a customer their deposit was received is a statement. Those are records in the ordinary legal sense, and the fact that they arrived through a mail server rather than an envelope changes nothing about their status.
Equally, most of a normal mailbox is not a record of anything. A quote that went nowhere, a scheduling back-and-forth, a supplier newsletter, an internal "can you cover Thursday" - these document no transaction and support no figure on a return. There is no legal obligation to keep them. Whether you do is an operational preference, not a compliance decision.
The statutory duty, in plain terms
Every person carrying on business, and every person required to pay or collect tax, must keep records and books of account in such form and containing such information as will enable the taxes payable to be determined [1]. That is the core obligation. It is outcome-based: the test is whether your records let the amount be worked out, not whether you filed them in a particular way.
On timing, the general rule is that records must be retained, together with every account and voucher necessary to verify the information in them, until six years from the end of the last taxation year to which the records relate [1]. Note the phrasing - the last taxation year to which the records relate, not the date the document was created. A supply agreement signed in 2024 that governs invoicing through 2027 relates to 2027, so its clock runs from the end of that year, not from the day it was signed.
The GST/HST side works the same way. Under the Excise Tax Act, every person who carries on a business or is engaged in a commercial activity in Canada, files a return under that Part, or applies for a rebate or refund, must keep all records necessary to enable the determination of their liabilities and obligations [3]. Those records must be retained until six years after the end of the year to which they relate [3]. That Act also says that unless the Minister authorizes otherwise, records are to be kept in Canada in English or in French [3] - a detail worth knowing if you are deciding where your business mail is stored.
Four things that extend the clock
The six-year figure gets quoted as if it were the whole rule. It is the default, and several provisions override it.
- An unfiled return. Where a return for a taxation year was not filed as and when required, the records relating to that year must be kept until six years from the day the return is actually filed [1]. Skipping a filing does not shorten your obligation - it suspends the start of it.
- An objection or appeal. If you serve a notice of objection or become a party to an appeal to the Tax Court, you must retain every record, book of account, account and voucher necessary for dealing with it until the time to appeal has elapsed or the appeal and any further appeal are disposed of [1]. The Excise Tax Act imposes the same duty for GST/HST objections, appeals and references [3].
- A written demand. Where the Minister considers it necessary for administering the Act, a demand can be served by registered letter or personally requiring records to be retained for a specified period [1]. The Excise Tax Act contains a matching power [3].
- Certain corporate records. The Income Tax Regulations prescribe separate periods: minutes of directors' and shareholders' meetings, records of share ownership and transfers, the general ledger or other book of final entry, and special contracts or agreements necessary to understand entries in it, are kept until two years after the corporation is dissolved [2]. For a corporation that is still operating, that means indefinitely.
There is a release valve in the other direction too. Both Acts let you dispose of records before the end of the period if the Minister gives written permission [1][3]. That is a formal process, not a judgment call you make yourself.
"Electronically readable" is a real requirement
This one gets missed. Where a person required to keep records does so electronically, they must retain them in an electronically readable format for the retention period [1]. The Excise Tax Act says the same [3]. Both Acts allow the Minister to exempt a person or class of persons from that requirement on acceptable terms [1][3], but you should not plan around an exemption you have not asked for.
The practical consequence is that "I have a backup somewhere" is not automatically compliance. If your archive is a proprietary export from mail software you stopped paying for, or an encrypted disk whose password left with a former bookkeeper, or a format nothing you own can open, you are holding data but not a readable record. Anything portable - standard mailbox exports, PDFs, plain files - stays readable for the length of a six-year window. Anything vendor-locked might not.
The other direction: privacy law says stop hoarding
Here is what makes this question genuinely two-sided rather than "keep everything, be safe". PIPEDA applies to every organization in respect of personal information it collects, uses or discloses in the course of commercial activities [5]. Personal information means information about an identifiable individual [5], and the Act's own definition of record includes correspondence and memoranda regardless of physical form, plus any copy of them [5]. Customer email is squarely inside all three definitions.
Principle 5 of Schedule 1 then states that personal information shall be retained only as long as necessary for the fulfilment of the purposes for which it was collected [4]. The guidance under it goes further: organizations should develop retention guidelines including minimum and maximum periods, and personal information no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous [4]. The same clause acknowledges that an organization may be subject to legislative requirements on retention periods [4] - which is exactly how the tax rules and the privacy rules coexist: keep what the law requires, for as long as it requires, and let the rest go.
So indefinite retention of everything is not the safe default it looks like. A ten-year-old mailbox full of customer addresses, phone numbers, health-related notes and payment discussions is personal information being held past its purpose - and it is also the blast radius of any future incident. On that point, note that PIPEDA requires an organization to keep and maintain a record of every breach of security safeguards involving personal information under its control [5], and the regulations set that record-keeping period at 24 months after the day the organization determines the breach occurred [6]. More retained mail means a bigger breach to record, disclose and explain.
The honest concession
Now the part most compliance writing leaves out. For a typical small business, mailbox storage is cheap and sorting old mail is expensive. An owner who spends six hours a year triaging correspondence to delete messages that cost a few dollars to store is losing money on the exercise. Broad retention is often the reasonable practical answer, and pretending otherwise makes for tidy advice and bad economics.
The real discipline is not aggressive deletion. It is two narrower habits:
- Know what you cannot delete. The transaction trail, the agreements, the objection-related correspondence, the corporate records under Regulation 5800 [2]. These need to survive a mailbox migration, a laptop failure and a staff departure - which means they should not exist only inside one person's inbox.
- Know what you should not be hoarding. Bulk personal information with no live purpose: old applicant resumes, a decade of customer identity documents someone emailed in, health or financial details captured for a job that closed years ago. That material is the part where "keep everything" turns into a liability rather than an insurance policy.
Everything between those two poles - ordinary work correspondence with no personal-information payload and no evidentiary role - can be kept broadly without much thought. That is the honest shape of the problem.
A note on precision
The retention periods above come from the statutes and regulations themselves, and they are written in general terms because the Acts apply to everyone from a sole proprietor to a bank. Your own situation may involve provincial statutes, industry regulators, employment records or professional obligations with their own periods, and tax administration publishes its own guidance on how the general rules apply in specific cases. Treat this article as the shape of the rules, and confirm the exact obligations for your business and your year-ends with the tax administration or your accountant before you destroy anything.
Do this this week
Pick one thing: find the last three transactions your business completed and check whether the documenting email exists anywhere other than one person's inbox. If the answer is no, that is your actual retention risk - not the length of the period, but the single point of failure holding the record. Export those threads, or the attachments, into whatever folder your bookkeeping already lives in. Then write down, in three lines, which categories of mail your business must keep and which contain customer personal information. That short list is a retention policy, and it is more than most small businesses have.