There is no number in the statute. That is the answer, and it is why so many businesses keep everything forever.

Canadian privacy law sets a test, not a period, and a test with no default is easy to never apply.

Canadian privacy law does not give a number. PIPEDA requires that personal information be retained only as long as necessary to fulfil the purpose it was collected for, which makes retention a judgement the business has to make and be able to defend. The practical consequence is that a business which never makes the decision inherits one: usually its vendor's default, chosen for the vendor's convenience, and applied identically to audio, transcripts and structured data that have completely different useful lives.

What does the law actually require?

That information be kept only as long as necessary for the purpose it was collected for, and then destroyed, erased or made anonymous. The purpose you named at the start of the call is what sets the clock, which is the reason the recording notice and the retention period are the same decision made twice.

This connects two things businesses usually handle separately. If the stated purpose is quality assurance and training, the honest question is how long a recording is useful for quality assurance and training. For most service businesses that is weeks, not years. If the stated purpose is dispute resolution, the answer is longer and tied to how long disputes realistically surface.

A purpose broad enough to justify indefinite retention is a purpose that was probably too broad to satisfy the consent requirement in the first place. The two obligations constrain each other, which is a useful check.

Should audio and transcripts have the same retention period?

Usually not. They carry different risk and different value. The audio contains a voice, which is identifying in ways text is not; the transcript is what actually gets used for quality review and search. Keeping both for the same period means keeping the riskier artefact as long as the useful one for no operational reason.

Three artefacts from one call, three different lives
ArtefactWhat it is useful forRetention consideration
Audio recordingVerifying what was actually said, tone, dispute resolutionHighest sensitivity: a voice is identifying. Shortest defensible period.
TranscriptQuality review, search, training, summariesModerate. Useful longer than audio for most purposes.
Structured fieldsName, callback number, appointment, outcomeBusiness records. Governed by why you keep customer records at all.

A single retention setting applied to all three is the most common configuration and the hardest to justify.

How do you choose a period you can defend?

Start from the purpose you told callers, ask how long that purpose genuinely needs, write the answer down, and configure the system to enforce it automatically. A retention policy that depends on someone remembering to delete things is a policy that describes an intention rather than a practice.

One vendor question is worth asking before any of this: is retention configurable per line, and can a specific individual's data be deleted on request? A platform that only offers one global setting makes a per-purpose decision impossible, and a platform that cannot delete one person's data cannot support an access or deletion request.

  • Name the purpose in one sentence. If it takes a paragraph, it is several purposes.
  • Ask how long that purpose needs. Quality review is measured in weeks; dispute resolution in months.
  • Set audio shorter than transcripts unless you have a specific reason not to.
  • Automate it. Manual deletion is the control most likely to be missing when checked.
  • Check whether your sector imposes a longer minimum; where it does, that governs.

Canadian privacy law gives you a test rather than a number for call retention, and a test with no default is easy to never apply, so the period most businesses actually run is whichever one their vendor shipped with.

Nick Lovett, Founder, AnswerAI

Retention is a question we ask during the build, not after, because the calls recorded before anyone decided are the ones a review asks about.

Start free pilot

What this page does not cover

This is a reading of the legislation as it applies to an AI receptionist answering a business phone, not legal advice. Statutes are amended and regulators publish new guidance; check the source links, which are dated, and take advice on anything that matters.

  1. Sector minimums. Financial services, health and legal practice carry record-keeping obligations that can require far longer retention than privacy law would suggest. Where they apply, they govern.
  2. Litigation holds. Anticipated or active litigation changes what may be destroyed, and overrides a routine retention schedule.
  3. A recommended number. This page deliberately does not name a period. Any number offered without knowing your stated purpose would be invented.

Questions this raises

How long does PIPEDA say I can keep call recordings?
It does not name a period. The requirement is to retain personal information only as long as necessary to fulfil the purpose it was collected for, then destroy, erase or anonymise it.
Is it safer to keep recordings longer, in case of a dispute?
Not from a privacy standpoint. Retaining longer than the stated purpose requires is itself the compliance failure, and it enlarges what a breach would expose. Dispute resolution can be a legitimate purpose; it just has to be the purpose you actually stated.
Can we keep transcripts but delete the audio?
Yes, and it is often the sensible split. Transcripts serve most operational purposes, while audio carries a voice and the higher sensitivity that comes with it.
Who is responsible if the vendor keeps recordings longer than we intended?
The business. Under PIPEDA's accountability principle an organization remains responsible for personal information transferred to a third party for processing, which is why the configurable-retention question belongs in vendor selection.
What if a caller asks us to delete their recording?
You need a process that can find and remove one individual's data. Whether the request must be granted depends on the circumstances, but being unable to act on it at all is its own problem.

Sources

  1. PIPEDA fair information principlesOffice of the Privacy Commissioner of Canadaconsulted 2026-08-09
  2. Recording of Customer Telephone Calls: guidance for organizationsOffice of the Privacy Commissioner of Canadaupdated 2018-04-18, consulted 2026-08-09
Nick Lovett

Nick Lovett

Founder, AnswerAI

Nick Lovett builds AI receptionists for service businesses across North America, and writes these from the call data they produce. Lovett Ventures Inc., Calgary.

Want an AI receptionist built around these rules rather than despite them?

We build a working receptionist on your calls, your booking rules and your escalation rules, and you call it yourself before committing to anything. About 14 days, no call limit during the pilot.

Start free pilot