Personal information in a daycare: PIPEDA, consent and retention
A daycare holds health data about children. That is the most sensitive category there is, and it calls for precise rules.
Published on September 8, 2026 · M2atech Solutions Inc.
A daycare holds information on each child that no other organisation in the neighbourhood holds: allergies, medications, medical history, parent contact details, sometimes elements of family circumstances. This is sensitive personal information, about people who cannot consent for themselves.
This guide summarises what the Personal Information Protection and Electronic Documents Act, known as PIPEDA, implies for a childcare service's daily work. It does not replace legal advice.
What the law asks, in practice
PIPEDA is built on principles rather than procedures. For a daycare, four of them shape most of the work.
- Limit collection: ask only for what actually serves keeping the child safe and billing the service.
- Obtain valid, meaning informed, consent for every use beyond that purpose.
- Protect information with safeguards proportional to its sensitivity, which primarily targets health data.
- Keep data only as long as necessary, then destroy it.
Consent is not a single checkbox
Many daycares have one registration form signed and consider consent settled for everything. That is the most widespread mistake, because uses are not equivalent.
Taking a photo of a child for the daily report sent to their parents is not the same as publishing that photo on a public page. Administering medication, applying sunscreen, authorising an outing or water activities are all distinct uses, each calling for an identifiable and revocable authorisation.
Three practical consequences: a consent attaches to a specific use, it carries a date, and it can be withdrawn. A system that cannot say who consented to what and since when cannot demonstrate compliance.
How long to keep it
The law sets no universal period: it asks that data be kept as long as needed for the purpose, then destroyed. A daycare therefore has different periods depending on the type of document.
| Type of data | Retention logic |
|---|---|
| Accounting and tax records | Period required by the tax administration, independent of other rules |
| Child file, medical information | The duration of attendance, then a reasonable period after departure |
| Messages and routine communication | Short period, to be defined and actually applied |
| Login logs and technical traces | Short period, useful for security only |
The hard part is not setting these periods but applying them. A policy announcing deletion after two years when no deletion ever happens is riskier than an honest policy announcing long retention.
What parents can ask for
A parent may request access to the information held about their child, obtain a copy, have an inaccuracy corrected and, within limits, request deletion. A daycare must be able to respond within a reasonable time.
The difficulty is rarely legal: it is material. Gathering a child's information scattered across a filing cabinet, a spreadsheet, an inbox and a chat group takes days. Gathering it from a single system takes minutes.
If a breach occurs
A breach of security safeguards creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to the individuals affected, and recorded. That applies to a computer intrusion as much as to a laptop left in a vehicle.
- Document the incident when it is discovered: what was exposed, how many people, for how long.
- Assess the real risk of significant harm before concluding, rather than after deciding not to report.
- Keep the breach register, including incidents judged low risk: that register is what will be asked for.
Staff, a frequent blind spot
Daycare policies talk about children and parents, rarely about employees. Yet a daycare also holds personal information about its staff: contact details, social insurance number, certifications, criminal record checks, sometimes medical information tied to a leave.
The same principles apply: collection limited to what is necessary, access restricted to those who need it, retention limited in time. A record check does not need to stay visible to the whole administrative team, and a certificate expired five years ago has no reason to be kept.
Three habits that lower the risk
Most daycare incidents come not from a computer attack but from ordinary use with no boundaries.
- Avoid personal channels: a consumer messaging group among educators ends up holding photos of children and health information, outside any daycare control.
- Give each person their own access rather than a shared account: a shared account makes it impossible to know who viewed what, and closing it when someone leaves never happens.
- Remove access on the day someone leaves, not at month end: it is the simplest action and the most often forgotten.
These three habits cost nothing and cover a large share of the situations that otherwise become a reportable incident.
Further reading
The Office of the Privacy Commissioner of Canada publishes guidance for organisations, and the text of the Act is available online.
Sources
- Office of the Privacy Commissioner of Canada — PIPEDA
- Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5)
KidSecure encrypts sensitive data, logs consents with their date, applies configurable retention periods and lets you export or delete a child's file on request.
Discover KidSecure
