Storage is cheap. That is most of the problem.
If you have been generating or buying leads for a few years, you are sitting on a database that grew in the background while you were busy doing everything else. Nobody sat down and decided to keep ten years of applications. It just never came up as a decision, and the default answer to "should we delete this?" is almost always "let's keep it, we might need it someday."
So here is a better question than the one people usually ask. Not "how long are we allowed to keep this?" but "why are we still keeping it?"
There is no magic number
Canadian privacy law does not give you one retention period for leads. There is no seven year rule sitting in a statute somewhere waiting to be looked up, and anyone who tells you there is has probably borrowed it from tax records.
Retention is tied to purpose. You keep information for as long as you actually need it for the reason you collected it, plus whatever a separate law requires you to hold. That means two fields sitting side by side in the same record can have very different lifespans. A consent timestamp and a stated annual income are not the same kind of data and should not automatically get the same treatment.
Proof that something happened is not the same as the lead
On the lead generation side there are real reasons to keep records. Proof of consent. Which buyer received which lead. Billing, reconciliation and chargeback disputes. Fraud patterns. Complaints and regulator questions that show up long after the click.
All of that is a good argument for keeping evidence of the transaction. It is not an argument for keeping the entire consumer profile. You may well need to show, three years from now, that a form was submitted at a specific date and time from a specific URL, that a specific version of the consent language was on the page, and that the lead went to two named buyers. You almost certainly do not need that person's income, employer, date of birth and street address to prove any of it.
An old lead is not a customer
Buyers have their own reasons: application processing, follow up, customer records, vendor performance analysis, and the recordkeeping that comes with being a licensed lender. Fair enough. Someone who actually borrowed money is a different situation, and those files often have to stay put.
The person who filled out a form in 2019, never answered the phone and never became a customer is not that situation. That is the record worth asking about. If there is no live sales process, no dispute, no legal hold and no obligation attached to them, what is the reason their full application is still sitting readable in production?
Consent records are their own bucket
This is where teams get nervous, so it is worth separating out. Deleting an old lead does not have to mean erasing every trace that the person existed. In a lot of cases you can keep the compliance evidence and drop everything else:
- Date and time consent was obtained
- Source URL and the form used
- The exact consent wording and version that was shown
- The parties, or categories of parties, the consumer agreed to hear from
- Withdrawal and unsubscribe records
- Suppression entries
Suppression data especially has to survive your own cleanup process. If a deletion job wipes the record of someone who unsubscribed, you will eventually mail them again, which is the one outcome nobody wants. Under CASL the sender is the party who has to prove consent existed, so that evidence is worth protecting long after the rest of the lead is gone. If you run email at any scale, treat suppression records with the same care you give your authentication and deliverability setup.
You can keep the numbers without keeping the people
Say you want to know the conversion rate on Ontario personal loan leads that came from Google Ads in 2022. That is a useful thing to know, and it is the reason a lot of old data never gets touched.
But look at what the question actually needs: province, vertical, source, campaign, date range, outcome. It does not need a name, an email, a phone number or an employer. Aggregate the performance data, strip the direct identifiers, and keep campaign level reporting in its own place. You get to keep the institutional memory without keeping an ever growing list of identifiable Canadians.
What Law 25 and PIPEDA actually say
In plain terms, Quebec's Law 25 runs on purpose and necessity. You collect for a stated purpose, you use it for that purpose, and once those purposes have been achieved the expectation is that the information is destroyed or anonymized, subject to retention periods set out in other legislation. "We might find a use for it later" is not a purpose. Worth knowing too that anonymization has a real standard attached to it in Quebec, so dropping the name column and calling it anonymous does not get you there. If you run traffic or buy leads in the province, we went through the rest of that regime in what affiliates get wrong about Quebec.
Federally, PIPEDA lands in a similar place with softer wording: keep personal information only as long as you need it for the purposes you identified, have actual guidelines and procedures for retention and destruction, and hold information used to make a decision about someone long enough that they can still ask to see it. Several provinces have their own private sector legislation layered on top, and federal reform is in motion, which we broke down in our piece on Bill C-36.
One distinction to hold on to. The legislation sets a direction and a principle. The specific numbers you land on are a business judgment, and most of what follows here is good practice rather than a legal requirement.
The breach math nobody runs
Here is the version of this argument that tends to land with people who find privacy law abstract. Every record you keep is part of your breach exposure.
Take a company generating a million leads a year. After ten years, the shop that kept everything is holding roughly ten million identifiable records. The shop that applied a real retention and anonymization policy is holding a fraction of that, with the rest reduced to performance data nobody can be re-identified from. Both look identical right up until the morning they do not.
When something does go wrong, the gap shows up everywhere: the size of the notification population, how sensitive the exposed fields are, what the investigation costs, the tone of the coverage, and how interested a regulator becomes. Meanwhile that decade old data was doing close to nothing for the business and would have been quite valuable to whoever took it.
The safest personal information in a data breach is the information you no longer have.
So how long should you keep a lead?
Rather than pretend there is a prescribed number, run each category of data through the same short set of questions.
| Ask this | What you are really deciding |
|---|---|
| Why was it collected? | The original stated purpose, in writing |
| Is that purpose still active? | Where the lead sits in the sales or application lifecycle |
| Is retention legally required? | Accounting, licensing and other regulatory obligations |
| Could we keep less? | Which fields you can drop and still meet the purpose |
| Could it be anonymized? | Whether your analytics needs people or just numbers |
| Do we need consent evidence? | CASL and privacy complaint defence |
| What happens if it leaks? | Sensitivity multiplied by volume |
Run that grid honestly and the categories start sorting themselves out. An active sales window is measured in weeks. A reconciliation and dispute window is measured in months, maybe a year or two. Consent evidence usually outlives both. Anonymized performance data can stay as long as it is useful. Those are illustrations of how we think about it rather than standards, and your own numbers will depend on your products, your partners and your obligations.
Put it in writing, then put it in your contracts
A retention policy does not have to be long, but it does have to be specific. It should identify the categories of data you collect, the purpose behind each one, how long each is kept, the business or legal justification, when identifiers get stripped, what gets anonymized, what gets destroyed, how backups are handled, how consent and suppression records are treated separately, who owns enforcement, and how legal holds work. Backups are the part everyone forgets, and they are exactly where deleted data quietly lives on.
Then push it into your agreements. Lead contracts should cover what the buyer is permitted to do with the data, what security is expected, how long it can be retained, how consumer deletion and withdrawal requests get handled, who notifies whom about a breach, and whether the data can be passed to any further party. On the buying side this is part of the same vendor review you should already be running, which we laid out in our lead provider due diligence checklist. And if you generate leads, hold your own affiliates and publishers to the standard you are promising your buyers.
Do not keep data just because you can
Collect what you need. Use it for a defined purpose. Keep it while you have a real reason. Preserve the compliance evidence. Anonymize what you can. Delete the rest.
None of this is legal advice, and retention interacts with enough other obligations that you want counsel looking at your policy before you start deleting anything. But the instinct behind it is simple enough. If you cannot say why you are still holding a record, that is your answer.