Step 2 of 922%
2

Personal Information Inventory: The Law 25 Data Register

Identify and document all the personal information your business holds.

Estimated time: 1 to 2 hours
Updated July 30, 2026

This is often the step that takes the longest, but it is the foundation for everything else.

The essentials

Taking inventory of personal information means mapping what data your business holds, where it is stored, who has access to it and how long you keep it. It is the starting point of any Law 25 compliance effort.

The law does not require a document called an "inventory register", but the exercise is unavoidable in practice: you cannot write your governance policies, answer an access request within 30 days or manage a confidentiality incident without knowing what data you hold.

A simple register, even a spreadsheet, is enough for most small businesses: data type, source, location, who has access, retention period.

What the law says

Law 25 requires every organization to know precisely what personal information it holds, for what purposes, where it is stored and who has access to it.

This inventory must include:

  • The nature of the information collected (name, address, date of birth, financial information, etc.)
  • The source of the data
  • How it is used
  • Where and for how long it is kept
  • The people or departments who have access to it
  • The protection measures in place

For a small business

Even a small business must be able to quickly present a complete picture of the personal information it holds. This can be done with:

  • An Excel or Google Sheets spreadsheet
  • A paper register stored in a secure location
  • A dedicated management tool if the volume is significant

🔍 Data that often gets overlooked

Do not forget to include in your inventory:

  • Resumes of unsuccessful job applicants
  • Archived emails containing client information
  • System backups
  • Former employees' access rights that were never revoked
  • Files on USB keys or external drives

Good to know

Without an up-to-date inventory, you cannot properly respond to a client's access request or effectively manage a confidentiality incident. In an audit, the absence of an inventory can be treated as a breach of your obligations.

Concrete examples

Example 1: A hair salon collects its clients' names, phone numbers and appointment history.

The inventory shows:

  • Type: personal contact details
  • Source: appointment booking form
  • Use: scheduling and reminders
  • Location: online management software hosted in Canada
  • Retention: 2 years after the last appointment
  • Protection: strong password, access restricted to the manager and stylists

Example 2: An online store collects its customers' billing and shipping information.

The inventory shows:

  • Type: name, address, email, purchase history, payment information (via Stripe)
  • Source: order form on the website
  • Use: order processing, delivery, customer service, newsletters (with consent)
  • Location: Shopify (servers in Canada), Stripe (payments), Mailchimp (newsletters)
  • Retention: 7 years for billing data (tax requirement), 2 years for the rest
  • Protection: two-factor authentication, access limited to the owner and the assistant

Why the inventory is the foundation of your compliance

Almost every Law 25 obligation assumes you know your data. Section 3.2 of the P-39.1 Act (in French) requires policies governing the retention and destruction of information: to write them, you need to know what you keep. The law also requires you to destroy or anonymize information once the purposes for which it was collected have been fulfilled.

The inventory also serves as proof of diligence: if the CAI questions you after a complaint or an incident, an up-to-date register shows that your business manages its information in a structured way.

The information almost everyone forgets

Failed inventories rarely miss the obvious (the CRM, the client list). They miss the blind spots: mailboxes accumulating years of attachments, forgotten exports and backups on a workstation, resumes of unsuccessful job applicants, data on former clients and former employees, and personal devices used for work.

A good technique: follow the journey of a fictional client from first contact to billing, then that of an employee from hiring to departure. Every tool or document encountered along the way goes into the inventory.

The standard inventory register, column by column

ColumnQuestion it answersExample
Type of informationWhat do you hold?Name, email, purchase history
SourceWhere does the data come from?Website contact form
LocationWhere is it stored?Cloud CRM, local server, paper filing cabinet
AccessWho can view it?Owner and administrative assistant
PurposeWhy do you hold it?Billing, after-sales service
RetentionFor how long?7 years after the last transaction (tax obligations)

Mistakes to avoid

  • Forgetting data held in emails or paper documents
  • Not specifying the retention period
  • Not updating the inventory after a system or process change
  • Confusing personal information with general business information

Step-by-step instructions

1
Identify every source of personal information collection
2
List the types of information collected
3
Determine what it is used for and who has access to it
4
Locate where it is physically and/or digitally stored
5
Record the retention period and the protection measures
6
Document everything in an official register

Checklist: Step 2 complete?

  • I have identified all my data collection sources
  • I have listed every type of personal information held
  • I have documented use, access and retention period
  • I have created an official register
  • I have a process to keep the register up to date

Templates included in the Law 25 Kit

  • Personal Information Inventory Register template
  • Personal Information Retention and Destruction Policy template
Get these templates

Frequently asked questions

Is the inventory register required by law?

Not under that name. The law does, however, require you to know, govern and limit the information you hold (purposes of collection, retention, destruction). The inventory register is the practical tool that lets you meet those obligations and prove it.

What data should be inventoried?

Any information that can identify a person: clients (contact details, purchase history), employees (HR files, payroll), suppliers, job applicants. Also think about the data inside your tools: CRM, newsletter, accounting, mailboxes.

How often should it be updated?

Whenever you add a new collection process (new form, new tool, new campaign) and during an annual review. An outdated inventory gives a false sense of compliance.

How long can personal information be kept?

As long as necessary for the purposes for which it was collected, subject to applicable legal retention periods (tax rules, for example). After that, the law requires you to destroy or anonymize it.