Data protection

Personal information in a daycare: PIPEDA, consent and retention

A daycare holds health data about children. That is the most sensitive category there is, and it calls for precise rules.

Published on September 8, 2026 · M2atech Solutions Inc.

A daycare holds information on each child that no other organisation in the neighbourhood holds: allergies, medications, medical history, parent contact details, sometimes elements of family circumstances. This is sensitive personal information, about people who cannot consent for themselves.

This guide summarises what the Personal Information Protection and Electronic Documents Act, known as PIPEDA, implies for a childcare service's daily work. It does not replace legal advice.

What the law asks, in practice

PIPEDA is built on principles rather than procedures. For a daycare, four of them shape most of the work.

Consent is not a single checkbox

Many daycares have one registration form signed and consider consent settled for everything. That is the most widespread mistake, because uses are not equivalent.

Taking a photo of a child for the daily report sent to their parents is not the same as publishing that photo on a public page. Administering medication, applying sunscreen, authorising an outing or water activities are all distinct uses, each calling for an identifiable and revocable authorisation.

Three practical consequences: a consent attaches to a specific use, it carries a date, and it can be withdrawn. A system that cannot say who consented to what and since when cannot demonstrate compliance.

How long to keep it

The law sets no universal period: it asks that data be kept as long as needed for the purpose, then destroyed. A daycare therefore has different periods depending on the type of document.

Type of dataRetention logic
Accounting and tax recordsPeriod required by the tax administration, independent of other rules
Child file, medical informationThe duration of attendance, then a reasonable period after departure
Messages and routine communicationShort period, to be defined and actually applied
Login logs and technical tracesShort period, useful for security only

The hard part is not setting these periods but applying them. A policy announcing deletion after two years when no deletion ever happens is riskier than an honest policy announcing long retention.

What parents can ask for

A parent may request access to the information held about their child, obtain a copy, have an inaccuracy corrected and, within limits, request deletion. A daycare must be able to respond within a reasonable time.

The difficulty is rarely legal: it is material. Gathering a child's information scattered across a filing cabinet, a spreadsheet, an inbox and a chat group takes days. Gathering it from a single system takes minutes.

If a breach occurs

A breach of security safeguards creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to the individuals affected, and recorded. That applies to a computer intrusion as much as to a laptop left in a vehicle.

Staff, a frequent blind spot

Daycare policies talk about children and parents, rarely about employees. Yet a daycare also holds personal information about its staff: contact details, social insurance number, certifications, criminal record checks, sometimes medical information tied to a leave.

The same principles apply: collection limited to what is necessary, access restricted to those who need it, retention limited in time. A record check does not need to stay visible to the whole administrative team, and a certificate expired five years ago has no reason to be kept.

Three habits that lower the risk

Most daycare incidents come not from a computer attack but from ordinary use with no boundaries.

These three habits cost nothing and cover a large share of the situations that otherwise become a reportable incident.

Further reading

The Office of the Privacy Commissioner of Canada publishes guidance for organisations, and the text of the Act is available online.


Sources

KidSecure encrypts sensitive data, logs consents with their date, applies configurable retention periods and lets you export or delete a child's file on request.

Discover KidSecure
Kid Secure

The intelligent management platform for daycares and CPEs in Canada.

App StoreGoogle Play
Contact

support@kidsecure.ca

Moncton, NB, Canada



© 2026 KidSecure. All rights reserved.