You can keep in your CRM any data that still serves the reason you collected it. That is Law 25's single criterion, and it is simpler than its reputation suggests: no list of forbidden fields, no universal retention period. A name, an email, a purchase history and follow-up notes are easy to justify for an active customer. The same data on a prospect who has not replied in four years no longer is.
Here is how to apply that criterion field by field, and what to delete today in most Quebec SMB CRMs. For the general framework, see what Law 25 changes for your marketing. This is not legal advice.
Purpose, and nothing else
The law sets two requirements that hang together. You collect only what is necessary for the stated purposes, and you destroy or anonymise the data once those purposes are fulfilled. So there is no general answer to how long can we keep a contact: the answer depends on what you do with it, and you have to be able to explain it.
The test is verbal, and it works well in a meeting. Take a field and finish the sentence out loud: we keep this data because… If the sentence ends in a precise business reason, the field stays. If it ends in you never know, it came with the import or it has always been there, the field goes. In the CRMs we open, that second case easily accounts for a third of the columns.
You never know is not a purpose. It is an admission that there is no longer one.
What needs no defending
For an active or recent customer, the core raises no issue: name, business contact details, company, quote and invoice history, contracts, job tracking, correspondence tied to the mandate. A good part of it falls under tax and accounting obligations that impose their own retention periods, and those take precedence over the urge to tidy. You do not delete an invoice in order to comply with Law 25.
Sales tracking data is equally defensible while the relationship is alive: call dates, pipeline stage, products discussed, objections raised. That is the material used to follow up at the right moment, and the purpose is easy to state.
What has to come out
Four categories come up every time. Personal data unrelated to the transaction, first: a date of birth collected to send birthday wishes, family situation, a social insurance number picked up nobody remembers why, scans of ID left as attachments. Then raw financial data: a full credit card number has no business sitting in a contact record, and your payment processor already handles it.
Third, imported lists whose origin nobody knows — a trade show file, a database inherited from a former salesperson, an export from a partner. With no source and no documented consent, you are holding information you cannot justify. And finally duplicates and ghost records: three entries for the same person triple your risk surface and your chances of getting it wrong the day an access request lands.
The case of free-text notes
This is every CRM's blind spot. The notes field accumulates years of hastily written comments, sometimes by people no longer with the company: difficult client, complains constantly, going through a divorce, wait, does not seem to have the money. Those notes are personal information exactly like everything else, and the person concerned has the right to see them on request.
The rule to give your team fits in one sentence: write nothing you would not be comfortable reading back to the person on the phone. That is not only a compliance instruction, it is a quality one — factual notes (stated budget of $15,000, decision in March, decision-maker is the brother) serve the sale; mood notes serve nobody.
How long to keep a prospect who never bought
The law gives no figure, so it is up to you to set a period and be able to explain it. The reasoning follows your real sales cycle. If you sell roofing, where the decision spreads over two or three seasons, keeping a quote request for three years is easy to defend. If you sell a service decided on in three weeks, four years of silence no longer justifies itself.
Write that period down somewhere — one line in an internal document is enough, and it feeds straight into your privacy policy. The exercise has an unexpected virtue: it forces you to look at how many contacts are asleep in the system having never been followed up. Most SMBs discover at that point that they have a follow-up problem well before they have a compliance problem.
Your CRM is hosted elsewhere: so what?
Most Quebec SMBs use an American tool, and that is not forbidden. What the law asks is that protection remains adequate outside Quebec, that the supplier contract provides for it, and that you can say in your privacy policy where the data goes. The large suppliers offer contractual addenda built for this; you just have to have signed them rather than assumed them.
The same logic applies to your newsletter platform, your booking tool and your agency: each holds a share of your customer data, and the responsibility always comes back to you. Make the list once — most SMBs find eight or ten where they had announced three. The email side, which has its own rules, is covered in our piece on consent and the newsletter.
The day somebody asks for their data
You have thirty days to answer a request for access, correction or deletion. The deadline is not the problem: the problem is knowing where that person's data lives. If it is in the CRM, in the newsletter platform, in an inbox, in a spreadsheet on somebody's desktop and in a message thread with the agency, the request turns into an internal investigation.
That is the best argument for centralising. A CRM holding everything, with clean exports, turns an access request into ten minutes of work. And if you are still weighing tools, see what to look at before choosing a CRM as a Quebec SMB — and in the meantime, book the diagnostic call: we open your system, look at what is in there, and you leave with the list of what has to come out.
