Canada's proposed Bill C-36 would replace PIPEDA with the Protecting Privacy and Consumer Data Act (PPCDA). The headline change is stronger penalties and a new regulator, but the deeper shift is in the default: organizations would have to stop retaining personal information the moment the original purpose runs out. For HR teams, that turns a comfortable habit — keep employee records forever, just in case — into an active liability.
What the bill actually says about retention
Bill C-36 says an organization must not retain personal information longer than necessary to fulfill the purpose it was collected for, comply with law, or meet the reasonable terms of a contract. Once that period ends, the organization must dispose of the information as soon as feasible. It also says organizations must take the sensitivity of the information into account when setting the retention period. (Bill C-36, section 52, parl.ca.)
There is no default seven-year rule. The law does not say "keep it for this long." It says "keep it only as long as you have a reason." That is a much harder standard to meet.
Who decides the reason and the duration?
A layered retention policy sounds reasonable in theory. In practice, each layer needs an owner:
- Statutory retention. Tax records, ROEs, employment standards files. These are dictated by statute and relatively easy to map.
- Contractual retention. Severance agreements, non-solicitation clauses, benefits commitments. Legal and HR policy set these.
- Operational retention. Performance history, training records, compensation decisions. HR and the business have to agree on why the data is still needed.
- Sensitivity-based retention. Health information, investigation files, accommodation records. These often need shorter retention and tighter access.
- Disposition. Someone has to actually delete or destroy the data, prove it happened, and handle backups, integrations, and vendor copies.
The problem is not the statutory layer. The problem is everything below it. Who signs off on the operational purpose for a ten-year-old performance review? Who decides when a departed employee's home address and emergency contact become disposable? Most organizations have never documented those decisions in a formal records retention schedule.
Most HRIS are not built for this
Most human capital management platforms are built around the employee record as the atomic unit. Payroll, benefits, time off, documents, notes, and performance reviews all hang off one profile in the employee master data model. The system assumes you keep the profile as long as the person is employed, and often long after. There is rarely a clean way to age out parts of the record while keeping others.
This architecture makes purpose-based disposition hard in at least five ways:
- One lifecycle per employee. You cannot assign different retention rules to different fields or record types without custom work.
- Partial disposition is fragile. You cannot easily redact or delete a home address and personal notes while keeping the role history that feeds your analytics.
- Reporting depends on named data. Turnover, compensation, and headcount trends are often built directly from employee profiles, so disposing of personal data threatens the reports.
- No native de-identification. Most HCM systems do not have a feature that converts an employee record into an anonymous workforce data point.
- Copies spread everywhere. Payroll systems, onboarding tools, ATS, finance systems, and backups all hold fragments of the same record.
Until HR platforms separate personal data from de-identified workforce analytics, HR teams will be stuck with manual exports, spreadsheets, and risky workarounds. The law will ask for a layered retention schedule; the systems will still be designed to keep everything in one place forever.
Management has to accept less historical access
Even with the right records schedule and system, the culture has to change. Managers are used to opening an employee file and seeing the full history. Under a purpose-based model, older personal information will not be there. "We might need it someday" stops being a valid reason.
This is where most data governance programs stall. Legal writes a policy, IT approves a tool, and then a director asks for a five-year-old investigation note and the whole system bends back to convenience. A retention schedule that is ignored whenever someone important asks for old data is not a retention schedule.
Practical ways to close the gap quickly
Most organizations will not have perfect systems on day one. A few interim moves can reduce risk while the architecture catches up.
Field-level redaction. While the full retention schedule is being designed, mask or restrict access to the most sensitive personal data. This does not solve disposition, but it limits exposure and buys time.
Build industry-level retention standards. If every company invents its own schedule, employees moving between employers get inconsistent protection. Industry HR groups should agree on baseline retention periods for common record types. That raises the floor for everyone and gives vendors a clear target.
Move workforce analytics to position-centric structures. Turnover patterns, compensation banding, and time-to-fill analytics should not require named employee records. If the analytics layer is role-based and de-identified, the personal layer can be disposed of sooner while the business intelligence remains.
The bottom line
Bill C-36 is not really a storage problem. It is a records governance problem. The law says organizations must know why they are keeping every piece of personal information and must dispose of it when that reason expires. For HR, that means moving from employee-record-centric systems to layered, purpose-based data architecture. The companies that adapt early will have cleaner systems, lower liability, and fewer surprises. The ones that wait will find that "keep everything" has become a very expensive habit.
AI disclosure: This post was drafted with AI assistance and reviewed by Kyle Yuen.