# Data Minimization for Children's Records

> Holding children's data longer than you need is a risk. How to collect less, limit who sees it, and dispose of records safely under BC's PIPA.

Published: 2026-09-04  
Author: Andrey (OpenCommunity Team)

## Key takeaways

- PIPA sets a floor as well as a ceiling: information you used to make a decision that directly affects someone must be kept for at least a year before you can dispose of it.
- The less children's data you hold and the fewer people who can see it, the smaller your risk if something goes wrong.
- Have a simple plan for responding if children's information is lost or exposed.

## Why holding data is a liability

It is tempting to keep every record forever, just in case. With children's information, that instinct works against you. Every birthdate, address, and family detail you store is something you have to protect, and something that could be exposed. Data you have deleted cannot be breached. Under BC's PIPA, keeping information you no longer need is not just clutter, it runs against the expectation that you hold personal information only as long as you have a reason to.

## Minimize before you store

The cheapest data to protect is the data you never collected. Before a record ever reaches storage, trim it. For each field, ask whether a program decision actually depends on it. Prefer a caregiver's contact over a child's, use age bands instead of exact birthdates where a birthday is not needed, and avoid free-text notes that invite oversharing.

This connects directly to how you build your intake forms. For more on what counts as a child's personal information in the first place, see [protecting children's personal information in BC programs](https://opencommunity.ca/blog/protecting-childrens-personal-information-community-programs-bc/index.md).

## Limit who can see it

Not everyone who volunteers at your centre needs to see every child's file. PIPA expects you to protect information with safeguards suited to how sensitive it is, and the simplest safeguard is limiting access by role. A greeter checking someone in does not need medical notes. A program lead might.

A single system where you can set who sees what is far safer than a shared spreadsheet that everyone can open. Keeping records in one place also means fewer stray copies on personal laptops and in email.

## How long to keep it: the one-year floor, then disposal

There is no single retention number for children's program records, because it depends on why you hold them. But minimizing does not mean deleting early: PIPA sets a **minimum** you must keep as well as a principle for when to let go, and the minimum is the part people miss.

If you use someone's personal information **to make a decision that directly affects them**, PIPA requires you to keep that information for **at least one year** after you use it, so the individual has a reasonable opportunity to ask for access to it. In a community program that covers more than you might expect: a fee-subsidy or sliding-scale decision, a program-eligibility or waitlist determination, and an incident report you relied on to restrict or exclude a family. Clearing those records out at the end of the season would put you offside, so treat the one-year mark as a floor, not a target.

Above that floor the principle is the familiar one: keep personal information only as long as it serves the purpose you collected it for, or as long as a law requires, then securely destroy or anonymize it. Some records carry their own rules. A gift that was tax-receipted, for instance, has receipting records you must keep under CRA rules regardless of the child's involvement. So set a retention schedule: decide, for each type of record, how long you keep it and when you dispose of it, and write it down. For the general picture beyond children's programs, see [how long a nonprofit should keep participant records](https://opencommunity.ca/blog/how-long-keep-participant-records/index.md), and confirm any legal retention periods that apply to your own programs.

> Tip: Disposal means secure disposal. Shred paper and properly delete digital files, rather than leaving old records in an unlocked drawer or a shared folder.

## If something goes wrong

Even careful organizations have incidents: a lost binder, a misdirected email, a stolen laptop. Have a simple plan. Currently, BC's PIPA does not require you to report a breach to the OIPC, but the OIPC recommends notifying affected individuals, and the regulator, when there is a real risk of significant harm. For children, that usually means telling the parents or guardians promptly and plainly.

This area is changing, and other rules may apply. Organizations covered by federal PIPEDA face mandatory breach reporting, and Alberta and Quebec already require it. If children's data is involved, err toward telling families. Check the current requirements with the OIPC.

> Note: This article is general information only and is not legal, financial, or professional advice. For questions about your organization's obligations, consult a qualified professional or the relevant government resource (for example, the CRA for registered charity matters, or your provincial or territorial registry for nonprofit governance).

## Questions and answers

### What is the minimum time we have to keep a child's record in BC?

At least one year, if you used that information to make a decision that directly affects the child or their family, such as a fee subsidy, an eligibility determination, or an incident report. PIPA gives the individual that year to request access. Past the floor, keep a record only as long as its purpose lasts or a law requires, then securely destroy or anonymize it.

### Do we have to report a privacy breach in BC?

Currently, reporting a breach to the BC OIPC is not mandatory under PIPA, but the OIPC recommends notifying affected individuals and the regulator when there is a real risk of significant harm. Rules differ federally and in other provinces, and BC's may change.

### What does data minimization mean?

Collecting and keeping only the personal information you actually need for a clear purpose. For children's programs, that means fewer fields, less sensitive detail, and shorter retention.

### Can we keep records in a shared spreadsheet?

You can, but it is harder to secure and to limit access. A single system where you control who sees what generally protects sensitive children's data better than a spreadsheet everyone can open.

### Who should we tell if children's data is exposed?

Usually the affected families first, promptly and in plain language, and the OIPC where there is a real risk of significant harm. Confirm the current requirements, since they vary by law and are evolving.

## More from OpenCommunity

- [All resources](https://opencommunity.ca/blog/index.md): Browse every published guide.
- [OpenCommunity features](https://opencommunity.ca/features/index.md): Explore the platform.