“Keep everything forever” is not a retention schedule, and neither is guessing. Four separate federal clocks apply to the same file, they start on different days, and RECO itself publishes none of them — here is how to build one schedule that actually satisfies all four.
Key takeaways
STEP 01 OF 10
The instinct to build a single “keep for X years” rule fails here, because no single rule actually governs a real estate file. Four distinct federal regimes apply, each with its own trigger, clock length, and starting point: FINTRAC’s AML/KYC records (five years, multiple sub-clocks), the Income Tax Act’s general business records (six years), PIPEDA’s mandatory breach-record rule (24 months, regardless of whether the breach was reportable), and — if you have incorporated — a separate, shorter ITR clock for your PREC’s corporate records. Treat these as four overlapping schedules, not one, and keep the longest applicable clock for anything a record could plausibly serve.
STEP 02 OF 10
FINTRAC’s guidance sets every retention period at five years, but the day the clock starts is not the same across record types. A Suspicious Transaction Report copy runs five years from the day it was submitted. A large cash transaction record runs five years from the day the record was created. An information record, and a business-relationship record, both run five years from the day of the last business transaction conducted — which for an active repeat client can be much later than the transaction the record originally documented. Mislabel a record with the wrong sub-clock and you either destroy it early or keep it needlessly long.
STEP 03 OF 10
Section 230(4)(b) of the Income Tax Act requires retaining business records “until the expiration of six years from the end of the last taxation year to which the records and books of account relate.” This is longer than FINTRAC’s five years and runs from a different starting point — the end of a tax year, not the date of a transaction. Section 230(5) adds a sharp edge: where no return was filed for a year at all, the records for that year must be kept indefinitely, because the six-year clock never starts running.
STEP 04 OF 10
This is the retention obligation most agents do not know exists. Section 10.3 of PIPEDA requires an organization to “keep and maintain a record of every breach of security safeguards” — and this duty is independent of whether the breach meets the reporting threshold. The Breach of Security Safeguards Regulations fix the period at 24 months from the day the organization determines the breach occurred. A lost laptop with no evidence of actual access still has to be logged for two years, even if you correctly conclude it does not meet the “real risk of significant harm” threshold that would require reporting it to the Commissioner.
STEP 05 OF 10
Once an agent structures through a Personal Real Estate Corporation, a second, distinct ITR clock applies to the corporation’s own records. Regulation 5800(1)(a)–(b) sets minute books, share-ownership records, and the corporate ledger to be retained “two years after the day that the corporation is dissolved” — a shorter period than the sole-proprietor six-year rule, but one that only starts running at dissolution, potentially decades after the records were created. A PREC does not shorten your overall retention obligation; it adds a second, dissolution-triggered clock on top of the personal one.
STEP 06 OF 10
The Excise Tax Act sets its own retention rule, but it lands on the same number as the ITA: section 286 requires records enabling determination of GST/HST liabilities to be kept, in English or French, in Canada, for six years after the year they relate to. In practice this means your GST/HST records and your general business records can sit on the same retention schedule without a separate calculation — the ITA’s six-year clock is the one to build around for both.
STEP 07 OF 10
Take every record type you actually hold — deal files, disclosure acknowledgements, ID verification documents, correspondence, financial-benefit disclosures, breach logs — and tag each with all of the regimes that could apply to it, then retain on the longest clock that applies. A deal file, for instance, sits under both FINTRAC’s five-year information-record clock and the ITA’s six-year clock; keep it six years, and confirm the FINTRAC-specific sub-records (identification, beneficial ownership) inside it are not destroyed early under a shorter internal assumption.
STEP 08 OF 10
Section 230(4.1) of the ITA requires that where records are kept electronically, they be retained “in an electronically readable format” — a scanned image that cannot later be searched or exported on request is a weaker position than a properly structured digital record. Confirm your CRM or document-management system can actually export a complete, readable file on request before you rely on it as your system of record; a platform you cannot extract from cleanly is a retention liability, not a retention solution.
STEP 09 OF 10
A RECO file review and a FINTRAC compliance examination ask for materially different things. RECO’s review, discussed in the complaint response guide, wants the representation agreement, disclosures and their acknowledgements, and correspondence. A FINTRAC examination wants the identification records, beneficial-ownership documentation, and business-relationship records specifically — see the FINTRAC compliance starter kit for what that file needs to contain. Keep both sets current and separable, so either request can be answered without reconstructing anything under time pressure.
STEP 10 OF 10
A schedule that only says when to keep something, never when to stop, accumulates risk of its own — PIPEDA’s limiting-retention principle runs in the other direction too, and a file kept indefinitely past every applicable clock is itself a data-minimization problem waiting to surface in a future privacy review. Set a review date on every retention category, and document the destruction itself — date, method, and what was destroyed — so the schedule can prove compliance in both directions, not just that nothing was thrown away too soon.
A deal closes and the last business transaction with this client is conducted on June 10, 2026. The agent’s tax year ends December 31, 2026. Five months later, on November 1, 2026, a separate privacy incident is discovered and logged. The agent later incorporates a PREC and dissolves it on January 15, 2030.
Four records tied to overlapping facts, four different expiry dates spanning more than five years from earliest to latest. The deal file itself has to survive until the latest applicable date that touches it — here, December 31, 2032 under the ITA — even though the FINTRAC-specific clock on the same underlying transaction would have permitted destruction more than a year earlier, on June 10, 2031. A schedule built around only one of these regimes destroys real records too early.
FINTRAC and the Income Tax Act are federal and identical everywhere in Canada. Privacy law is not — three provinces run their own regime instead of PIPEDA.
| Jurisdiction | Which privacy law actually applies | What this means for your schedule |
|---|---|---|
| Most of Canada (incl. Ontario) | PIPEDA governs directly — confirmed for Ontario, Manitoba, the Maritimes, and the territories. | The 24-month breach-record clock in Step 4 applies as stated. |
| Alberta, British Columbia, Quebec | Each has its own private-sector privacy statute, deemed “substantially similar” to PIPEDA for handling wholly inside the province — but PIPEDA still governs the moment information crosses a provincial or national border, which most cloud CRMs do by default. | Confirm your own provincial statute’s breach-record retention period before assuming PIPEDA’s 24 months applies to a purely intra-provincial file. |
| Quebec, specifically | A separate OACIQ-administered regulation — the Regulation respecting records, books and registers, trust accounting and inspection of brokers and agencies (C-73.2, r. 4) — sits alongside the privacy statute and governs recordkeeping for the brokerage relationship itself. | The specific retention periods in that regulation were not fetched for this guide — confirm them directly with OACIQ rather than assuming Ontario’s FINTRAC/ITA figures transfer. |
No — RECO publishes no deal-file retention period of its own. The clocks that actually govern the file come from FINTRAC, the Income Tax Act, and (for privacy incidents) PIPEDA, each running independently.
Yes, in most cases the ITA’s six-year clock still applies to ordinary business records regardless of whether FINTRAC reporting was triggered. Only FINTRAC’s specific report-copy retention (five years) is tied to an actual report having been filed.
No — section 230(5) is explicit that where no return was filed, the records for that year must be kept indefinitely, because the six-year clock never starts.
Yes. Section 10.3’s record-keeping duty applies to every breach, reportable or not — the 24-month clock runs regardless of whether the breach ever crossed the reporting threshold.
We help brokerages turn FINTRAC, ITA, and PIPEDA's retention rules into a single, defensible calendar.