The information life cycle
Every piece of information goes through five stages. At each one, a compliance question arises.
| Stage | Question to ask | Example |
|---|---|---|
| Collection | Is it necessary? Is the person informed? | Free-trial sign-up form |
| Use | Is it consistent with the announced purposes? | Using support emails for marketing: no, without new consent |
| Disclosure | To whom, why, under what contract? | Sending data to a transactional email service |
| Retention | For how long? Where? Who has access? | 24-month retention rule for logs |
| Destruction / anonymization | When purposes are fulfilled, destroy or anonymize | Automatic purge after a customer leaves |
Golden rule
When the purposes for which information was collected are fulfilled, the organization must destroy it or anonymize it for serious and legitimate purposes (s. 23 and Anonymization Regulation). Keeping it "just in case" is not a sufficient reason.
Example (school). Records of students who have left are not kept forever: a retention schedule approved by the principal sets what to keep, for how long, and when to destroy.
Outside Québec
Disclosing information outside Québec (e.g. cloud hosting in the United States) requires a prior assessment (PIA): more on this in the role-based modules.