The short answer
When someone leaves, revoke their login first, convert the mailbox to an archive rather than deleting it, forward the address to whoever now owns those customer relationships, and set a deliberate retention date. Tax records law generally expects six years; privacy law expects you to keep no longer than necessary.
A staff departure is one of the few moments where a small business can lose a decade of customer history and create a privacy exposure in the same afternoon. It rarely feels like a risky moment. Someone hands in a key, everyone is friendly about it, and the email account just sits there - still logged in on a phone, still receiving quotes requests, still holding the only copy of what your business promised a customer three years ago.
Nothing dramatic happens that week. The cost shows up months later, when a customer replies to a thread at an address nobody reads, or when you need to prove what was agreed and the only record left the building.
The order matters more than the tools
There are four steps and the sequence is the whole trick. Do them out of order and you either lock yourself out of records you need, or leave a live door open while you are busy tidying.
One: revoke the credential, not the mailbox. Change the password and terminate every active session and connected device. Not "ask them to log out" - actually end the sessions. A departing person is rarely the threat; the phone they still carry, sitting on a coffee shop network with a saved password, is a more realistic one. PIPEDA's safeguards principle is explicit that protection should include organizational measures such as limiting access on a need-to-know basis, alongside technological measures like passwords [1]. A person who no longer works for you has no need to know, and that is true whether the parting was warm or not.
Two: convert the mailbox, do not delete it. The instinct to clean up is exactly wrong here. That mailbox is likely the only place certain business records exist. Section 230 of the Income Tax Act requires every person carrying on business to keep records and books of account in a form that lets the taxes payable be determined [4]. Emailed invoices, supplier confirmations and quotes are part of how that determination gets made. Convert the account to a non-login archive - keep the data, remove the ability to sign in.
Three: redirect the address to whoever now owns the relationship. Every customer who has that address in their contacts will keep using it, for years. Point it at the person who has actually inherited those relationships, and pair it with an auto-reply that names them. A bounce message is a dead end for the customer. Silent acceptance is worse, because from the outside it looks like you read the message and chose not to answer.
Four: decide the retention period on purpose. Write a date down. This is the step everyone skips, and the reason so many small businesses are quietly storing every mailbox they have ever created.
Six years, and the tension underneath it
Two bodies of law pull in opposite directions here, and you need both numbers in your head.
On the keep-it side: the Income Tax Act requires records and books of account to be retained until six years from the end of the last taxation year to which they relate, and where no return was filed for a year, six years from the day the return for that year is eventually filed [4]. The Excise Tax Act sets the parallel rule for GST/HST - records retained until six years after the end of the year to which they relate, with electronic records kept in an electronically readable format for that same period, and kept in Canada in English or French unless the Minister authorizes otherwise [5]. If a dispute is live, the clock does not simply run out: both Acts extend retention while an objection or appeal is outstanding [4][5].
On the do-not-hoard side: PIPEDA's fifth principle says personal information shall be retained only as long as necessary for the fulfilment of the purposes it was collected for, and asks organizations to develop retention guidelines that include minimum and maximum periods [1]. Information no longer required for those purposes should be destroyed, erased or made anonymous, and the safeguards principle adds that care must be used in disposal so unauthorized parties cannot recover it [1].
Those are not contradictory once you stop treating a mailbox as one object. The invoice thread and the personal note to a friend have different answers. The practical resolution for a small business is to keep the archive for the tax window, restrict who can open it, and diarize the deletion rather than leaving it to drift.
The uncomfortable part: whose mail is it
Here is the tension worth being honest about, because most advice on this subject skips it.
A working mailbox is almost never purely business. Alongside the customer threads there is a dentist appointment, a message from a spouse, an application to another employer, a doctor's letter. Those are that person's personal correspondence, sitting inside an account your business owns. Ownership of the account does not make the contents fair reading.
PIPEDA applies to every organization in respect of personal information it collects, uses or discloses in the course of commercial activities [2], and its limiting principle says personal information shall not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law [1]. The information in a departed employee's mailbox was not collected so that you could browse it.
The workable line is purpose. Going into the archive to retrieve a specific customer thread, a specific invoice, a specific supplier agreement, because you have an actual business need for that record, is a defensible use. Reading through someone's mail because the account is now yours and you are curious is not. Restrict access to one or two people, note why the archive was opened when it is opened, and keep the retrieval narrow. That is not legal advice - it is the reading of the safeguards and limiting principles that a reasonable owner can defend, which for a business this size is what matters.
If you are unsure whether you can characterise a search as necessary, that hesitation is usually the answer.
The specific mistake: the account nobody closed
The single most common failure is not deletion. It is leaving the account fully alive, fully logged in, and completely unmonitored - because closing it felt final and nobody wanted to make the call.
That state is genuinely worse than either alternative. Customer mail arrives and dies. And you are holding an active credential on your domain that no employee is watching. If it is later used by someone who should not have it, you are in breach territory: PIPEDA requires an organization to report to the Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm to an individual [2]. Beyond reporting, you must keep a record of every breach of security safeguards - and the regulations set that record's life at 24 months after the day the organization determines the breach occurred [3].
An unmonitored account is also the hardest kind of incident to notice. Nobody is reading the mailbox, so nobody sees the sent items.
Fix it before the next departure: role addresses
The real repair is upstream, and it costs nothing. Anything a customer might use to reach the business should be a role address - sales@, accounts@, service@, bookings@ - not a person's name. Individuals still get a personal address for individual correspondence. But the address on your invoices, your van, your website and your quotes should be one you can reassign in sixty seconds without telling a single customer that anything changed.
Alongside that, keep a plain list of who owns which relationships and who inherits them. One page. It converts a departure from an archaeology project into a routing change.
The honest concession
Most small business departures are friendly. The person trained their replacement, said goodbye properly, and would never touch the account again. In that situation none of this feels necessary, and skipping it will very likely cost you nothing at all.
That is a fair reading of the odds. The reason to do it anyway is the asymmetry, not the risk of betrayal. The disciplined version takes about twenty minutes on the last day. The cost of skipping it does not show up as a dramatic incident - it shows up eight months later as a customer who replied to a dead address and concluded you were not interested, or an audit question you cannot answer because the thread lived in a mailbox somebody tidied away.
And if you genuinely have one mailbox, no shared customer inbox, and the departing person was the owner's spouse helping out for a season - convert the mailbox and move on. You do not need a policy document. You need the archive to still exist.
Do this this week
Open your mail admin and list every mailbox on your domain. For each one, answer two questions: is a person still using this, and would a customer write to it? Any mailbox that fails the first test and passes the second is a leak you already have. Convert it, forward it, and set the deletion date. Then pick the one address customers use most and make sure it is a role address, not a name - so the next time someone leaves, this article is a five-minute task instead of a project.