Card on CRA six-year email retention rules for Toronto finance teams. Why do Toronto finance teams configure email retention around CRA rules?
Image: Productivity Software Reviews

Rules

Why do Toronto finance teams configure email retention around CRA rules?

Productivity software reviews explain how Toronto finance teams set email retention around CRA six-year rules, the Income Tax Act, and GST/HST filing trails.

What to take away

  • Productivity software reviews of retention settings matter most in Toronto, where the country's largest cluster of corporate head offices sets policy for the whole company.
  • The CRA six-year record retention rule is federal law, and the Income Tax Act sections behind it decide how long email, attachments and filed returns must stay available.
  • Retention is configured in the mail platform, the file store and the finance system at once, because deleting one copy while another survives creates the worst outcome.
  • The CRA requires written permission before destroying records early, and an open audit or appeal keeps them alive.
  • Toronto head offices should test restore paths before a CRA review, not during one.

Why CRA record retention drives Toronto email policy

Toronto holds the largest concentration of corporate head offices and finance employers in Canada. The six-year CRA retention rule is federal law, not a Toronto-specific rule. Toronto head offices apply it as company policy.

Decisions about business email, file sharing and collaboration tools are usually made in the city. Branch offices in Ontario, Quebec, Alberta and British Columbia then inherit those settings.

That is why retention is rarely left to individual inboxes. A branch manager in another province cannot set a 90 day auto-delete rule that quietly destroys records the whole company needs. The CRA can ask for books and records years after a filing. The answer has to come from a system, not from someone's memory of a deleted thread.

The Canada Revenue Agency publishes the business tax guidance that finance teams build these rules on, covering filing, payment and record-keeping duties Business taxes - Canada.ca. Retention policy is downstream of that guidance, not a separate IT preference.

Toronto also sits inside a privacy layer that shapes how long records may be kept, not only how long they must be. PIPEDA applies federally, and Ontario has its own information and privacy commissioner. Quebec's Law 25 adds provincial obligations for companies with staff there.

Keep records long enough for tax, and no longer than the privacy rule allows.

The six-year rule and the Income Tax Act sections behind it

The CRA six-year record retention period is the baseline most Canadian finance teams work to. Records and books of account must generally be kept for six years from the end of the last tax year to which they relate. Section 230(4) of the Income Tax Act states the rule.

Records must be kept "for a period of six years from the end of the last taxation year to which the records and books of account relate."

For a corporation, that clock starts after the year the return covers, so the practical storage window runs longer than six calendar years.

Several Income Tax Act sections matter here. Section 230 requires every person carrying on business to keep records and books of account. Section 230.1 covers who must keep them and for how long. Section 238 sets out the consequences of failing to comply, and section 231.1 gives the CRA authority to inspect, audit and examine records.

Those sections are published in the federal statutes. The Department of Justice maintains the Consolidated Acts page where the Income Tax Act and related statutes appear in full Consolidated Acts.

Finance teams do not need to memorize section numbers, but the retention schedule should be traceable to them.

Two practical points follow. First, the six-year floor is a minimum, not a target: if a dispute, reassessment or appeal is open, retention continues. Second, the requirement is about records, not formats, so an email can satisfy it as easily as a PDF invoice.

How the clock actually runs

How the six-year clock runs

  1. End of tax year
    six-year retention clock starts
  2. Six years
    minimum retention from that date
  3. Open dispute, reassessment or appeal
    retention continues
  4. Corporation return year
    window runs past six calendar years

The CRA's own forms and publications set out retention periods and record-keeping requirements, and they are the version most auditors and finance staff actually work from CRA Forms and publications - Canada.ca.

What counts as a record when email is the ledger

A record is any document or information that supports the numbers on a return. An approval thread for a capital purchase, a vendor confirming a price change, a controller authorizing a journal entry: each can be the only evidence that a figure is correct.

What a retention policy must keep

Kept

Attachments
PDF invoice, credit note
Message body
explains the adjustment
Metadata
sender, recipient, date
Shared mailbox
record lives there
Collaboration copies
linked sheets, comments

Lost if stripped

Attachments
easy part
Message body
context gone
Metadata
auditor cannot trace
Shared mailbox
nobody owns it
Collaboration copies
pulled into review

Attachments are the easy part. The hard part is the message body that explains an adjustment, plus the metadata showing who sent it, to whom, and when. A retention policy that keeps attachments but strips message headers has destroyed the context an auditor needs.

Shared mailboxes and distribution lists complicate this further. When a finance team works out of a shared inbox, the record may live in a mailbox that nobody owns. No one thinks to include it in the retention schedule.

Collaboration tools add another copy. A spreadsheet linked from a chat message, a comment trail on a shared document, a task note recording an approval: all of it can be pulled into a review.

The record-keeping discipline used for legal matters, where retention, redaction and audit logs are treated as one problem, is a useful model for finance retention, redaction, and audit logs.

Worked example: a single GST/HST adjustment

Worked example: GST/HST adjustment

  1. A Toronto controller emails a supplier to confirm a credit note for a mischarged tax amount.
  2. The supplier replies with a PDF credit note and a revised invoice number.
  3. The controller posts the adjustment and files the return for the period.
  4. Two years later the CRA asks how the input tax credit was supported.
  5. The answer is the email thread, the PDF and the posting record, all still intact and linked.

If step 1 was set to auto-delete after twelve months, step 5 fails, even though the accounting system kept the journal entry.

How to set retention across mail, files and finance systems

Retention is a configuration task that spans several products, which is why it shows up so often in productivity software reviews. The mail platform holds messages, the file store holds attachments and working papers, and the finance system holds the posted entries. A policy that covers only one of the three leaves gaps.

Configuring retention across three systems

  1. Apply retention labels and holds in the mail platform
  2. Check licence tier for hold and eDiscovery features
  3. Map shared drives, sync clients and recycle bin clocks
  4. Decide the schedule for finance system exports

Start with the platform's native retention and litigation hold features. Most business email suites can apply a retention label by mailbox, folder or keyword, and can place a hold that overrides user deletion.

Understand what your licence tier includes, because hold and eDiscovery features are often priced separately. Business email pricing usually separates them from basic mailboxes business email pricing.

Litigation holds and CRA audit notices both suspend deletion. When a hold applies, the platform must keep the message even if the retention label says otherwise. A CRA audit notice works the same way: it freezes the retention clock for the records it covers.

Test that the hold actually blocks auto-delete, because a policy that only exists on paper will not stop a scheduled job.

Then map the file side. Shared drives, sync clients and collaboration spaces each keep their own versions and recycle bins, and those bins have their own clocks. Seat counts and forgotten retention are the two line items that surprise finance teams most when file sharing contracts renew forgotten retention.

Finally, decide what happens to the finance system's own exports. If a report is generated, emailed and then deleted from the reporting tool, the email may be the only surviving copy. That is an argument for keeping exports on a defined schedule rather than on demand.

A retention matrix Toronto teams can copy

Record typeTypical retentionWhere it lives
Corporate income tax return and working papersSix years from end of tax yearFinance system plus file store
GST/HST returns and supporting invoicesSix years from end of tax yearFinance system plus email
Payroll records and remittancesSix years from end of tax yearPayroll system
Approval and adjustment emailsSame as the record they supportMail platform with hold
Contracts and credit notesSix years after the contract endsFile store

A matrix like this is only useful if someone owns each row. Name the owner in the policy document, and review it when systems change.

Migration projects are the usual moment retention breaks, because old mailboxes get moved without their holds. Business email migration should always start with a clear scope business email migration.

GST/HST filing trails Toronto finance teams must preserve

GST/HST records carry their own expectations on top of the general six-year rule. Registrants must keep records supporting the tax collected and the input tax credits claimed.

GST/HST filing trail to preserve

  • Invoices supporting tax collected
  • Credit notes and receipts
  • Working papers behind each return
  • Advisor emails on multi-province tax treatment
  • Filing confirmations and acknowledgements

Invoices, credit notes, receipts and the working papers behind each return all count. The CRA's filing guidance shows what a return needs before submission, a useful checklist for what must be retained after How to file - File your GST/HST return - Canada.ca.

For a Toronto head office filing across several provinces, the trail has extra layers. A single return may cover sales in Ontario, Quebec, British Columbia, Alberta and elsewhere, with different tax treatment for some items. The email asking an advisor how to treat a particular line is part of the trail, not noise.

The CRA business account is where much of this becomes visible. Filing history, notices and balances sit there, and a finance team that keeps its own copy of confirmations and filing acknowledgements has a faster answer when something is questioned.

The CRA's tax services hub is the starting point for deadlines, account access and record obligations across the different tax types a company deals with Taxes - Canada.ca.

What to keep alongside the return

  • The filed return and the confirmation number.
  • The reconciliation between the accounting system and the return.
  • Supporting invoices and credit notes, including those exchanged by email.
  • Notes on any judgement call, such as place of supply or a partial exemption.

Auditing retention before a CRA review

A retention audit is cheaper than a failed one. Run it as a project with a defined scope, the same way a system migration would be scoped, and record what you find.

Start by listing every place a record can live: the mail platform, the file store, the finance system, payroll and any collaboration tool in use. Then check the retention setting on each. The most common finding is a platform default of indefinite retention on one system and aggressive deletion on another.

Test a restore. Pick a transaction from four years ago and try to produce the full trail within a working day. If it takes a week, the policy is not working regardless of what the settings say.

Finally, check that the tools can produce evidence in a usable form. Audit and export capability decides how painful a review becomes. It is also what makes business email software 2027 worth keeping: a searchable archive and export tools, not dashboards.

A pre-review checklist

Pre-review retention checklist

  • Retention schedule cites Income Tax Act sections
  • Every mail, file and finance system has an owner
  • Holds override user deletion on open matters
  • GST/HST support kept with its return
  • Four-year-old transaction rebuilt in one day
  • Exports and audit logs usable

Common questions

Does the six-year rule apply to email?
Yes, if the email supports a figure on a return or the books behind it. Format does not exempt a message.
Can we delete email after six years?
Usually, once no dispute, reassessment or appeal is open. The CRA requires written permission before you destroy records early, and an open audit or appeal freezes deletion. Check privacy limits and any industry rule first, and keep the deletion itself logged.
Who owns retention in a Toronto head office?
The controller or CFO owns the policy, IT owns the settings, and records management or legal arbitrates disputes. One named owner per system prevents gaps.
Do different provinces change the retention period?
The federal six-year rule applies across Ontario, Quebec, British Columbia, Alberta and the rest. Provincial privacy law can shorten what you may keep, not lengthen it.
What about Quebec's Law 25?
It adds privacy obligations for companies with Quebec operations, including limits on how long personal information is held. Retention schedules should satisfy tax minimums and privacy maximums together.
How do we prove a record was not altered?
Keep the original message with its headers, store it in a system with audit logs, and avoid re-saving files in ways that overwrite metadata.

More in Rules

Latest from Value Desk