When a driving school modernizes, the instinct is nearly always the same: digitize everything. Signed contracts, learner's licences, parental consents, proof of payment, medical certificates. You scan, you file, you feel finally in order.

It's an understandable instinct, and it's probably the decision that increases your risk the most for close to zero compliance benefit.

Here's why — and what to do instead.

What a verification actually asks

An inspection sets out to establish facts:

  • Did a service contract exist for this student?
  • Was their learner's licence valid at the time of the practical outings?
  • Was parental consent obtained, for a minor?
  • Did the sessions take place, on what dates, with which instructor?

Notice the shape of those questions. They're about the existence and validity of evidence — not requests to hand over a file.

So there are two ways to satisfy the same requirement, and they don't have remotely the same risk profile.

Two models

The vault. You keep a digital copy of every document. Everything is at hand, immediately. You have also built, without intending to, a database containing the identity documents of several hundred people, a large share of them minors.

The evidence register. For each required proof you record: whether it exists, where it's kept ("cabinet A, file 2026-014"), who verified it, and when. The original document stays in your filing cabinet, or in the system the school already uses.

Both answer the inspector. Only one creates a target.

Vault Evidence register
Answers an inspection Yes Yes
Content exposed in a breach Identity documents, medical records, signatures Statuses and locations
People affected by a breach Every student who submitted a document The same, but without the content
Effort to honour a deletion request Find every file One row
Transfers outside Québec (s. 17) The document itself leaves A status leaves

What a breach actually contains

This is the thought experiment that changes decisions.

Imagine your document storage is exposed tomorrow. What does someone have?

Under the vault model: learner's licences — government identifiers, with photo and date of birth. Parental consents bearing signatures. Sometimes medical documents. Much of it belonging to teenagers.

Under the register model: a list of your students and the fact that, for each, a given document exists and was verified on a given date.

The second is still a confidentiality incident — it must be recorded, and reported if it presents a serious risk of harm. But the gap between the two scenarios isn't a matter of degree. They're different categories of event.

The principle, in one sentence

What you don't store can't leak.

It's the most useful reasoning in all of Law 25, and the only one that saves you time instead of costing it. Every other measure — encryption, access control, backups, supplier agreements — protects what you hold. Minimization reduces what there is to protect.

Data you never collected needs no encryption, appears in no incident register, complicates no deletion request, and crosses no border.

The side effect on your suppliers

A benefit you don't see coming.

Under section 17, entrusting personal information to a supplier located outside Québec — including elsewhere in Canada — requires a prior assessment and a written agreement.

That obligation doesn't vanish if you only store statuses: a student's name is still personal information. But what crosses the border changes in nature. Sending "document D-4 exists, verified 12 March" is not the same exposure as sending a photograph of a driver's licence.

Your assessment becomes simpler to perform, and considerably simpler to defend.

Where the vault still makes sense

Let's be honest: minimization isn't an absolute rule.

If your school has good reasons to keep certain documents — an ongoing dispute, a specific contractual obligation, an internal process that requires it — then keep them. The principle isn't "store nothing", it's "store deliberately".

The difference between the two comes down to one question. For each document type you digitize, ask: what could I not do if I only had its status?

If the answer is "nothing concrete", you're carrying risk for free.

Check what you can produce

The useful test isn't "have I stored everything?" but "can I answer?":

Can you produce the evidence?

Each item restates an obligation you already have. The question isn't whether it exists, but whether you can demonstrate it. Nothing is saved.

0 of 9

0%

Start with contract dates: it's the field the most other answers depend on.

Your answers stay in your browser.

What you can do this week

  1. List the document types you currently digitize. Most schools have never written that list out explicitly.
  2. For each, ask the status question. What does the copy enable that the status wouldn't?
  3. Start with the most sensitive. Medical documents and minors' identity documents are the ones whose removal changes your risk profile the most.
  4. Decide, and write the decision down. A retention policy that exists only as habit isn't defensible.

The takeaway

  • An inspection asks whether evidence exists and is valid, not for a file.
  • The evidence register satisfies the same requirement as the vault, at a fraction of the risk.
  • A leak of statuses and a leak of minors' identity documents are not the same event.
  • Minimization also lightens your obligations on transfers outside Québec.
  • The principle isn't "store nothing", it's "store deliberately".

For how this applies to your situation — particularly if you have specific contractual obligations — confirm with a qualified advisor.