✉️ MapleMail
Business email operations

What to do with an employee email account when someone leaves

Revoke the login, convert the mailbox, redirect the address, decide the retention. Twenty minutes on the last day saves a year of missing customer history.

The short answer

When someone leaves, revoke their login first, convert the mailbox to an archive rather than deleting it, forward the address to whoever now owns those customer relationships, and set a deliberate retention date. Tax records law generally expects six years; privacy law expects you to keep no longer than necessary.

A staff departure is one of the few moments where a small business can lose a decade of customer history and create a privacy exposure in the same afternoon. It rarely feels like a risky moment. Someone hands in a key, everyone is friendly about it, and the email account just sits there - still logged in on a phone, still receiving quotes requests, still holding the only copy of what your business promised a customer three years ago.

Nothing dramatic happens that week. The cost shows up months later, when a customer replies to a thread at an address nobody reads, or when you need to prove what was agreed and the only record left the building.

The order matters more than the tools

There are four steps and the sequence is the whole trick. Do them out of order and you either lock yourself out of records you need, or leave a live door open while you are busy tidying.

One: revoke the credential, not the mailbox. Change the password and terminate every active session and connected device. Not "ask them to log out" - actually end the sessions. A departing person is rarely the threat; the phone they still carry, sitting on a coffee shop network with a saved password, is a more realistic one. PIPEDA's safeguards principle is explicit that protection should include organizational measures such as limiting access on a need-to-know basis, alongside technological measures like passwords [1]. A person who no longer works for you has no need to know, and that is true whether the parting was warm or not.

Two: convert the mailbox, do not delete it. The instinct to clean up is exactly wrong here. That mailbox is likely the only place certain business records exist. Section 230 of the Income Tax Act requires every person carrying on business to keep records and books of account in a form that lets the taxes payable be determined [4]. Emailed invoices, supplier confirmations and quotes are part of how that determination gets made. Convert the account to a non-login archive - keep the data, remove the ability to sign in.

Three: redirect the address to whoever now owns the relationship. Every customer who has that address in their contacts will keep using it, for years. Point it at the person who has actually inherited those relationships, and pair it with an auto-reply that names them. A bounce message is a dead end for the customer. Silent acceptance is worse, because from the outside it looks like you read the message and chose not to answer.

Four: decide the retention period on purpose. Write a date down. This is the step everyone skips, and the reason so many small businesses are quietly storing every mailbox they have ever created.

Six years, and the tension underneath it

Two bodies of law pull in opposite directions here, and you need both numbers in your head.

On the keep-it side: the Income Tax Act requires records and books of account to be retained until six years from the end of the last taxation year to which they relate, and where no return was filed for a year, six years from the day the return for that year is eventually filed [4]. The Excise Tax Act sets the parallel rule for GST/HST - records retained until six years after the end of the year to which they relate, with electronic records kept in an electronically readable format for that same period, and kept in Canada in English or French unless the Minister authorizes otherwise [5]. If a dispute is live, the clock does not simply run out: both Acts extend retention while an objection or appeal is outstanding [4][5].

On the do-not-hoard side: PIPEDA's fifth principle says personal information shall be retained only as long as necessary for the fulfilment of the purposes it was collected for, and asks organizations to develop retention guidelines that include minimum and maximum periods [1]. Information no longer required for those purposes should be destroyed, erased or made anonymous, and the safeguards principle adds that care must be used in disposal so unauthorized parties cannot recover it [1].

Those are not contradictory once you stop treating a mailbox as one object. The invoice thread and the personal note to a friend have different answers. The practical resolution for a small business is to keep the archive for the tax window, restrict who can open it, and diarize the deletion rather than leaving it to drift.

The uncomfortable part: whose mail is it

Here is the tension worth being honest about, because most advice on this subject skips it.

A working mailbox is almost never purely business. Alongside the customer threads there is a dentist appointment, a message from a spouse, an application to another employer, a doctor's letter. Those are that person's personal correspondence, sitting inside an account your business owns. Ownership of the account does not make the contents fair reading.

PIPEDA applies to every organization in respect of personal information it collects, uses or discloses in the course of commercial activities [2], and its limiting principle says personal information shall not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law [1]. The information in a departed employee's mailbox was not collected so that you could browse it.

The workable line is purpose. Going into the archive to retrieve a specific customer thread, a specific invoice, a specific supplier agreement, because you have an actual business need for that record, is a defensible use. Reading through someone's mail because the account is now yours and you are curious is not. Restrict access to one or two people, note why the archive was opened when it is opened, and keep the retrieval narrow. That is not legal advice - it is the reading of the safeguards and limiting principles that a reasonable owner can defend, which for a business this size is what matters.

If you are unsure whether you can characterise a search as necessary, that hesitation is usually the answer.

The specific mistake: the account nobody closed

The single most common failure is not deletion. It is leaving the account fully alive, fully logged in, and completely unmonitored - because closing it felt final and nobody wanted to make the call.

That state is genuinely worse than either alternative. Customer mail arrives and dies. And you are holding an active credential on your domain that no employee is watching. If it is later used by someone who should not have it, you are in breach territory: PIPEDA requires an organization to report to the Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm to an individual [2]. Beyond reporting, you must keep a record of every breach of security safeguards - and the regulations set that record's life at 24 months after the day the organization determines the breach occurred [3].

An unmonitored account is also the hardest kind of incident to notice. Nobody is reading the mailbox, so nobody sees the sent items.

Fix it before the next departure: role addresses

The real repair is upstream, and it costs nothing. Anything a customer might use to reach the business should be a role address - sales@, accounts@, service@, bookings@ - not a person's name. Individuals still get a personal address for individual correspondence. But the address on your invoices, your van, your website and your quotes should be one you can reassign in sixty seconds without telling a single customer that anything changed.

Alongside that, keep a plain list of who owns which relationships and who inherits them. One page. It converts a departure from an archaeology project into a routing change.

The honest concession

Most small business departures are friendly. The person trained their replacement, said goodbye properly, and would never touch the account again. In that situation none of this feels necessary, and skipping it will very likely cost you nothing at all.

That is a fair reading of the odds. The reason to do it anyway is the asymmetry, not the risk of betrayal. The disciplined version takes about twenty minutes on the last day. The cost of skipping it does not show up as a dramatic incident - it shows up eight months later as a customer who replied to a dead address and concluded you were not interested, or an audit question you cannot answer because the thread lived in a mailbox somebody tidied away.

And if you genuinely have one mailbox, no shared customer inbox, and the departing person was the owner's spouse helping out for a season - convert the mailbox and move on. You do not need a policy document. You need the archive to still exist.

Do this this week

Open your mail admin and list every mailbox on your domain. For each one, answer two questions: is a person still using this, and would a customer write to it? Any mailbox that fails the first test and passes the second is a leak you already have. Convert it, forward it, and set the deletion date. Then pick the one address customers use most and make sure it is a role address, not a name - so the next time someone leaves, this article is a five-minute task instead of a project.

Foire aux questions

Should I delete an employee mailbox when they leave?

Not on the last day, and usually not for a long time after. The mailbox almost certainly contains business records - quotes, invoices, supplier confirmations - that tax law expects you to be able to produce for six years. Delete the login immediately, keep the contents deliberately, and set a calendar date for the deletion instead of doing it in the moment.

What is the first thing I should do when someone leaves?

Revoke the credential, not the mailbox. Change the password and sign out every active session and device before you touch anything else. Everything after that - converting the mailbox, forwarding the address, exporting the archive - is easier and safer once nobody else can be reading along while you work.

Is it legal to read a former employee inbox?

It is a judgement call rather than a free-for-all. PIPEDA obliges you to limit how personal information is used to the purposes it was collected for and to restrict access on a need-to-know basis. Searching for a specific customer thread you need is defensible; browsing someone personal correspondence because you now can is not.

How long should I keep the mailbox archive?

Long enough to satisfy records law and no longer than you can justify. Income tax records generally run six years from the end of the last taxation year they relate to, and GST/HST records six years after the end of the year. PIPEDA pushes the other way and says personal information should be kept only as long as necessary for the purpose it was collected.

What happens if I just leave the old account running?

You get the worst outcome of both options. The address keeps accepting customer mail nobody is reading, so enquiries silently die, and you are still holding a live, unmonitored login attached to your domain. If that login is later abused, PIPEDA breach obligations can attach and you may have to keep a record of the incident.

Should mail to the old address bounce or forward?

Forward to whoever now owns the relationship, for a defined period, with an auto-reply naming the new contact. A bounce tells a customer nothing except that you are gone. Silent acceptance is worse still. Forwarding plus a reply gives the person a name to write to and gives you a chance to update your own records.

How do I avoid this scramble next time?

Move shared functions to role addresses - sales@, accounts@, service@ - before anyone leaves, and write down who inherits which relationships. Personal addresses are fine for personal correspondence, but any address a customer might use to reach the business should be one you can reassign in a minute.

Does any of this apply to a business with two employees?

The privacy principles apply to any organization handling personal information in the course of commercial activities, and the tax retention rules apply to every person carrying on business. Scale changes the effort, not the obligation. For a two-person shop the whole sequence is realistically twenty minutes.

Sources

  1. Personal Information Protection and Electronic Documents Act, Schedule 1 (Principles) — Clause 4.5 limiting use, disclosure and retention; 4.7 safeguards, including 4.7.3 organizational measures and need-to-know access, and 4.7.5 care in disposal
  2. Personal Information Protection and Electronic Documents Act (full text) — Section 4(1) application to commercial activities; section 10.1 breach reporting where there is a real risk of significant harm; section 10.3 record of every breach
  3. Breach of Security Safeguards Regulations, SOR/2018-64 — Section 6(1) - record of every breach of security safeguards kept for 24 months after the day the organization determines the breach occurred
  4. Income Tax Act, section 230 (Records and books) — Subsection 230(1) duty to keep records; 230(4)(b) six years from the end of the last taxation year; 230(5) six years from the filing day where no return was filed
  5. Excise Tax Act, section 286 (Records) — Subsection 286(1) records necessary to determine liabilities; 286(1.2) kept in Canada in English or French; 286(3) six years after the end of the year; 286(3.1) electronically readable format

Toutes les sources ont été vérifiées le 2026-08-28.

MapleMail runs your business email on your own domain, on Canadian-hosted infrastructure, with mailbox conversion, forwarding and archive retention handled from one place.

See plans and pricing