
Rules
Why do Toronto finance teams configure email retention around CRA rules?
Productivity software reviews explain how Toronto finance teams set email retention around CRA six-year rules, the Income Tax Act, and GST/HST filing trails.
What to take away
- Productivity software reviews of retention settings matter most in Toronto, where the country's largest cluster of corporate head offices sets policy for the whole company.
- The CRA six-year record retention rule is federal law, and the Income Tax Act sections behind it decide how long email, attachments and filed returns must stay available.
- Retention is configured in the mail platform, the file store and the finance system at once, because deleting one copy while another survives creates the worst outcome.
- The CRA requires written permission before destroying records early, and an open audit or appeal keeps them alive.
- Toronto head offices should test restore paths before a CRA review, not during one.
Why CRA record retention drives Toronto email policy
Toronto holds the largest concentration of corporate head offices and finance employers in Canada. The six-year CRA retention rule is federal law, not a Toronto-specific rule. Toronto head offices apply it as company policy.
Decisions about business email, file sharing and collaboration tools are usually made in the city. Branch offices in Ontario, Quebec, Alberta and British Columbia then inherit those settings.
That is why retention is rarely left to individual inboxes. A branch manager in another province cannot set a 90 day auto-delete rule that quietly destroys records the whole company needs. The CRA can ask for books and records years after a filing. The answer has to come from a system, not from someone's memory of a deleted thread.
The Canada Revenue Agency publishes the business tax guidance that finance teams build these rules on, covering filing, payment and record-keeping duties Business taxes - Canada.ca. Retention policy is downstream of that guidance, not a separate IT preference.
Toronto also sits inside a privacy layer that shapes how long records may be kept, not only how long they must be. PIPEDA applies federally, and Ontario has its own information and privacy commissioner. Quebec's Law 25 adds provincial obligations for companies with staff there.
Keep records long enough for tax, and no longer than the privacy rule allows.
The six-year rule and the Income Tax Act sections behind it
The CRA six-year record retention period is the baseline most Canadian finance teams work to. Records and books of account must generally be kept for six years from the end of the last tax year to which they relate. Section 230(4) of the Income Tax Act states the rule.
Records must be kept "for a period of six years from the end of the last taxation year to which the records and books of account relate."
For a corporation, that clock starts after the year the return covers, so the practical storage window runs longer than six calendar years.
Several Income Tax Act sections matter here. Section 230 requires every person carrying on business to keep records and books of account. Section 230.1 covers who must keep them and for how long. Section 238 sets out the consequences of failing to comply, and section 231.1 gives the CRA authority to inspect, audit and examine records.
Those sections are published in the federal statutes. The Department of Justice maintains the Consolidated Acts page where the Income Tax Act and related statutes appear in full Consolidated Acts.
Finance teams do not need to memorize section numbers, but the retention schedule should be traceable to them.
Two practical points follow. First, the six-year floor is a minimum, not a target: if a dispute, reassessment or appeal is open, retention continues. Second, the requirement is about records, not formats, so an email can satisfy it as easily as a PDF invoice.
How the clock actually runs
How the six-year clock runs
- End of tax yearsix-year retention clock starts
- Six yearsminimum retention from that date
- Open dispute, reassessment or appealretention continues
- Corporation return yearwindow runs past six calendar years
The CRA's own forms and publications set out retention periods and record-keeping requirements, and they are the version most auditors and finance staff actually work from CRA Forms and publications - Canada.ca.
What counts as a record when email is the ledger
A record is any document or information that supports the numbers on a return. An approval thread for a capital purchase, a vendor confirming a price change, a controller authorizing a journal entry: each can be the only evidence that a figure is correct.
What a retention policy must keep
Kept
- Attachments
- PDF invoice, credit note
- Message body
- explains the adjustment
- Metadata
- sender, recipient, date
- Shared mailbox
- record lives there
- Collaboration copies
- linked sheets, comments
Lost if stripped
- Attachments
- easy part
- Message body
- context gone
- Metadata
- auditor cannot trace
- Shared mailbox
- nobody owns it
- Collaboration copies
- pulled into review
Attachments are the easy part. The hard part is the message body that explains an adjustment, plus the metadata showing who sent it, to whom, and when. A retention policy that keeps attachments but strips message headers has destroyed the context an auditor needs.
Shared mailboxes and distribution lists complicate this further. When a finance team works out of a shared inbox, the record may live in a mailbox that nobody owns. No one thinks to include it in the retention schedule.
Collaboration tools add another copy. A spreadsheet linked from a chat message, a comment trail on a shared document, a task note recording an approval: all of it can be pulled into a review.
The record-keeping discipline used for legal matters, where retention, redaction and audit logs are treated as one problem, is a useful model for finance retention, redaction, and audit logs.
Worked example: a single GST/HST adjustment
Worked example: GST/HST adjustment
- A Toronto controller emails a supplier to confirm a credit note for a mischarged tax amount.
- The supplier replies with a PDF credit note and a revised invoice number.
- The controller posts the adjustment and files the return for the period.
- Two years later the CRA asks how the input tax credit was supported.
- The answer is the email thread, the PDF and the posting record, all still intact and linked.
If step 1 was set to auto-delete after twelve months, step 5 fails, even though the accounting system kept the journal entry.
How to set retention across mail, files and finance systems
Retention is a configuration task that spans several products, which is why it shows up so often in productivity software reviews. The mail platform holds messages, the file store holds attachments and working papers, and the finance system holds the posted entries. A policy that covers only one of the three leaves gaps.
Configuring retention across three systems
- Apply retention labels and holds in the mail platform
- Check licence tier for hold and eDiscovery features
- Map shared drives, sync clients and recycle bin clocks
- Decide the schedule for finance system exports
Start with the platform's native retention and litigation hold features. Most business email suites can apply a retention label by mailbox, folder or keyword, and can place a hold that overrides user deletion.
Understand what your licence tier includes, because hold and eDiscovery features are often priced separately. Business email pricing usually separates them from basic mailboxes business email pricing.
Litigation holds and CRA audit notices both suspend deletion. When a hold applies, the platform must keep the message even if the retention label says otherwise. A CRA audit notice works the same way: it freezes the retention clock for the records it covers.
Test that the hold actually blocks auto-delete, because a policy that only exists on paper will not stop a scheduled job.
Then map the file side. Shared drives, sync clients and collaboration spaces each keep their own versions and recycle bins, and those bins have their own clocks. Seat counts and forgotten retention are the two line items that surprise finance teams most when file sharing contracts renew forgotten retention.
Finally, decide what happens to the finance system's own exports. If a report is generated, emailed and then deleted from the reporting tool, the email may be the only surviving copy. That is an argument for keeping exports on a defined schedule rather than on demand.
A retention matrix Toronto teams can copy
| Record type | Typical retention | Where it lives |
|---|---|---|
| Corporate income tax return and working papers | Six years from end of tax year | Finance system plus file store |
| GST/HST returns and supporting invoices | Six years from end of tax year | Finance system plus email |
| Payroll records and remittances | Six years from end of tax year | Payroll system |
| Approval and adjustment emails | Same as the record they support | Mail platform with hold |
| Contracts and credit notes | Six years after the contract ends | File store |
A matrix like this is only useful if someone owns each row. Name the owner in the policy document, and review it when systems change.
Migration projects are the usual moment retention breaks, because old mailboxes get moved without their holds. Business email migration should always start with a clear scope business email migration.
GST/HST filing trails Toronto finance teams must preserve
GST/HST records carry their own expectations on top of the general six-year rule. Registrants must keep records supporting the tax collected and the input tax credits claimed.
GST/HST filing trail to preserve
- Invoices supporting tax collected
- Credit notes and receipts
- Working papers behind each return
- Advisor emails on multi-province tax treatment
- Filing confirmations and acknowledgements
Invoices, credit notes, receipts and the working papers behind each return all count. The CRA's filing guidance shows what a return needs before submission, a useful checklist for what must be retained after How to file - File your GST/HST return - Canada.ca.
For a Toronto head office filing across several provinces, the trail has extra layers. A single return may cover sales in Ontario, Quebec, British Columbia, Alberta and elsewhere, with different tax treatment for some items. The email asking an advisor how to treat a particular line is part of the trail, not noise.
The CRA business account is where much of this becomes visible. Filing history, notices and balances sit there, and a finance team that keeps its own copy of confirmations and filing acknowledgements has a faster answer when something is questioned.
The CRA's tax services hub is the starting point for deadlines, account access and record obligations across the different tax types a company deals with Taxes - Canada.ca.
What to keep alongside the return
- The filed return and the confirmation number.
- The reconciliation between the accounting system and the return.
- Supporting invoices and credit notes, including those exchanged by email.
- Notes on any judgement call, such as place of supply or a partial exemption.
Auditing retention before a CRA review
A retention audit is cheaper than a failed one. Run it as a project with a defined scope, the same way a system migration would be scoped, and record what you find.
Start by listing every place a record can live: the mail platform, the file store, the finance system, payroll and any collaboration tool in use. Then check the retention setting on each. The most common finding is a platform default of indefinite retention on one system and aggressive deletion on another.
Test a restore. Pick a transaction from four years ago and try to produce the full trail within a working day. If it takes a week, the policy is not working regardless of what the settings say.
Finally, check that the tools can produce evidence in a usable form. Audit and export capability decides how painful a review becomes. It is also what makes business email software 2027 worth keeping: a searchable archive and export tools, not dashboards.
A pre-review checklist
Pre-review retention checklist
- Retention schedule cites Income Tax Act sections
- Every mail, file and finance system has an owner
- Holds override user deletion on open matters
- GST/HST support kept with its return
- Four-year-old transaction rebuilt in one day
- Exports and audit logs usable







