Treadstone Associates
Guide

A record retention schedule you can defend

“Keep everything forever” is not a retention schedule, and neither is guessing. Four separate federal clocks apply to the same file, they start on different days, and RECO itself publishes none of them — here is how to build one schedule that actually satisfies all four.

Treadstone Associates · Updated 2026

Key takeaways

  • • RECO publishes no deal-file retention period of its own — the clocks that actually govern your file come from FINTRAC, the ITA, and PIPEDA instead.
  • • FINTRAC uses five years, but the clock starts on a different day for different record types — get this wrong and you destroy something before you were allowed to.
  • • The Income Tax Act requires six years from the end of the relevant tax year — longer than FINTRAC’s five, and running from a different starting point entirely.
  • • A privacy breach record has its own, much shorter federal clock: 24 months, and it applies even to a breach too minor to report to the Commissioner.

STEP 01 OF 10

Separate the four regimes before you build one schedule

The instinct to build a single “keep for X years” rule fails here, because no single rule actually governs a real estate file. Four distinct federal regimes apply, each with its own trigger, clock length, and starting point: FINTRAC’s AML/KYC records (five years, multiple sub-clocks), the Income Tax Act’s general business records (six years), PIPEDA’s mandatory breach-record rule (24 months, regardless of whether the breach was reportable), and — if you have incorporated — a separate, shorter ITR clock for your PREC’s corporate records. Treat these as four overlapping schedules, not one, and keep the longest applicable clock for anything a record could plausibly serve.

STEP 02 OF 10

Build the FINTRAC table correctly — the clock starts on different days by record type

FINTRAC’s guidance sets every retention period at five years, but the day the clock starts is not the same across record types. A Suspicious Transaction Report copy runs five years from the day it was submitted. A large cash transaction record runs five years from the day the record was created. An information record, and a business-relationship record, both run five years from the day of the last business transaction conducted — which for an active repeat client can be much later than the transaction the record originally documented. Mislabel a record with the wrong sub-clock and you either destroy it early or keep it needlessly long.

STEP 03 OF 10

Confirm the ITA’s six-year clock, and what happens if a return was never filed

Section 230(4)(b) of the Income Tax Act requires retaining business records “until the expiration of six years from the end of the last taxation year to which the records and books of account relate.” This is longer than FINTRAC’s five years and runs from a different starting point — the end of a tax year, not the date of a transaction. Section 230(5) adds a sharp edge: where no return was filed for a year at all, the records for that year must be kept indefinitely, because the six-year clock never starts running.

STEP 04 OF 10

Log every privacy breach on its own 24-month clock, reportable or not

This is the retention obligation most agents do not know exists. Section 10.3 of PIPEDA requires an organization to “keep and maintain a record of every breach of security safeguards” — and this duty is independent of whether the breach meets the reporting threshold. The Breach of Security Safeguards Regulations fix the period at 24 months from the day the organization determines the breach occurred. A lost laptop with no evidence of actual access still has to be logged for two years, even if you correctly conclude it does not meet the “real risk of significant harm” threshold that would require reporting it to the Commissioner.

STEP 05 OF 10

If you incorporate a PREC, know the corporate-records clock is shorter and starts differently

Once an agent structures through a Personal Real Estate Corporation, a second, distinct ITR clock applies to the corporation’s own records. Regulation 5800(1)(a)–(b) sets minute books, share-ownership records, and the corporate ledger to be retained “two years after the day that the corporation is dissolved” — a shorter period than the sole-proprietor six-year rule, but one that only starts running at dissolution, potentially decades after the records were created. A PREC does not shorten your overall retention obligation; it adds a second, dissolution-triggered clock on top of the personal one.

STEP 06 OF 10

Keep GST/HST records on the same clock as your income tax records

The Excise Tax Act sets its own retention rule, but it lands on the same number as the ITA: section 286 requires records enabling determination of GST/HST liabilities to be kept, in English or French, in Canada, for six years after the year they relate to. In practice this means your GST/HST records and your general business records can sit on the same retention schedule without a separate calculation — the ITA’s six-year clock is the one to build around for both.

STEP 07 OF 10

Build one master calendar with the longest applicable clock, not four separate trackers

Take every record type you actually hold — deal files, disclosure acknowledgements, ID verification documents, correspondence, financial-benefit disclosures, breach logs — and tag each with all of the regimes that could apply to it, then retain on the longest clock that applies. A deal file, for instance, sits under both FINTRAC’s five-year information-record clock and the ITA’s six-year clock; keep it six years, and confirm the FINTRAC-specific sub-records (identification, beneficial ownership) inside it are not destroyed early under a shorter internal assumption.

STEP 08 OF 10

Store records in an electronically readable format, and confirm your CRM actually is one

Section 230(4.1) of the ITA requires that where records are kept electronically, they be retained “in an electronically readable format” — a scanned image that cannot later be searched or exported on request is a weaker position than a properly structured digital record. Confirm your CRM or document-management system can actually export a complete, readable file on request before you rely on it as your system of record; a platform you cannot extract from cleanly is a retention liability, not a retention solution.

STEP 09 OF 10

Know what a file review actually asks for, and keep that specific set current

A RECO file review and a FINTRAC compliance examination ask for materially different things. RECO’s review, discussed in the complaint response guide, wants the representation agreement, disclosures and their acknowledgements, and correspondence. A FINTRAC examination wants the identification records, beneficial-ownership documentation, and business-relationship records specifically — see the FINTRAC compliance starter kit for what that file needs to contain. Keep both sets current and separable, so either request can be answered without reconstructing anything under time pressure.

STEP 10 OF 10

Set a destruction protocol, not just a retention one

A schedule that only says when to keep something, never when to stop, accumulates risk of its own — PIPEDA’s limiting-retention principle runs in the other direction too, and a file kept indefinitely past every applicable clock is itself a data-minimization problem waiting to surface in a future privacy review. Set a review date on every retention category, and document the destruction itself — date, method, and what was destroyed — so the schedule can prove compliance in both directions, not just that nothing was thrown away too soon.

Worked example: four clocks on the same file, four different expiry dates

A deal closes and the last business transaction with this client is conducted on June 10, 2026. The agent’s tax year ends December 31, 2026. Five months later, on November 1, 2026, a separate privacy incident is discovered and logged. The agent later incorporates a PREC and dissolves it on January 15, 2030.

  • • FINTRAC information/business-relationship record (5 years from last transaction, June 10, 2026): retain until June 10, 2031
  • • ITA general business record (6 years from the end of the 2026 tax year): retain until December 31, 2032
  • • PIPEDA breach record (24 months from determination, November 1, 2026): retain until November 1, 2028
  • • PREC corporate record (2 years from dissolution, January 15, 2030): retain until January 15, 2032

Four records tied to overlapping facts, four different expiry dates spanning more than five years from earliest to latest. The deal file itself has to survive until the latest applicable date that touches it — here, December 31, 2032 under the ITA — even though the FINTRAC-specific clock on the same underlying transaction would have permitted destruction more than a year earlier, on June 10, 2031. A schedule built around only one of these regimes destroys real records too early.

Where the privacy-law clock genuinely differs by province

FINTRAC and the Income Tax Act are federal and identical everywhere in Canada. Privacy law is not — three provinces run their own regime instead of PIPEDA.

JurisdictionWhich privacy law actually appliesWhat this means for your schedule
Most of Canada (incl. Ontario)PIPEDA governs directly — confirmed for Ontario, Manitoba, the Maritimes, and the territories.The 24-month breach-record clock in Step 4 applies as stated.
Alberta, British Columbia, QuebecEach has its own private-sector privacy statute, deemed “substantially similar” to PIPEDA for handling wholly inside the province — but PIPEDA still governs the moment information crosses a provincial or national border, which most cloud CRMs do by default.Confirm your own provincial statute’s breach-record retention period before assuming PIPEDA’s 24 months applies to a purely intra-provincial file.
Quebec, specificallyA separate OACIQ-administered regulation — the Regulation respecting records, books and registers, trust accounting and inspection of brokers and agencies (C-73.2, r. 4) — sits alongside the privacy statute and governs recordkeeping for the brokerage relationship itself.The specific retention periods in that regulation were not fetched for this guide — confirm them directly with OACIQ rather than assuming Ontario’s FINTRAC/ITA figures transfer.

Frequently asked

Does RECO tell you how long to keep a deal file?

No — RECO publishes no deal-file retention period of its own. The clocks that actually govern the file come from FINTRAC, the Income Tax Act, and (for privacy incidents) PIPEDA, each running independently.

If a client’s file never triggered a reportable transaction, do you still need to keep records?

Yes, in most cases the ITA’s six-year clock still applies to ordinary business records regardless of whether FINTRAC reporting was triggered. Only FINTRAC’s specific report-copy retention (five years) is tied to an actual report having been filed.

Can you destroy records once six years have passed if no tax return was ever filed for that year?

No — section 230(5) is explicit that where no return was filed, the records for that year must be kept indefinitely, because the six-year clock never starts.

Do you need a separate breach log if nothing was ever reported to the Privacy Commissioner?

Yes. Section 10.3’s record-keeping duty applies to every breach, reportable or not — the 24-month clock runs regardless of whether the breach ever crossed the reporting threshold.

Common mistakes

  • Applying FINTRAC’s five-year clock to every record type in a file. FINTRAC itself uses several different starting points by record type — see Step 2.
  • Assuming a PREC shortens your overall retention obligation. It adds a second, dissolution-triggered clock on top of the personal one — it does not replace it.
  • Destroying a record after six years without checking whether a return was ever filed for that year. Section 230(5) removes the clock entirely in that specific case.
  • Treating a non-reportable privacy incident as needing no record at all. PIPEDA’s section 10.3 duty to log a breach is independent of whether it met the reporting threshold.

Get a retention schedule built around all four clocks, not one.

We help brokerages turn FINTRAC, ITA, and PIPEDA's retention rules into a single, defensible calendar.