Most Canadian tax penalties can be resisted by showing that you took reasonable care. The provisions governing electronic sales suppression say, in terms, that you cannot. That is rare enough in this legislation to be worth a restaurant owner's attention even if they have never heard the phrase.

Key Takeaway

Following a 2013 British Columbia Court of Appeal decision holding that the sale of sales-deletion software was not then prohibited, Parliament enacted parallel provisions in the Income Tax Act and the Excise Tax Act effective January 2014. CRA states the administrative fines as $5,000 on a first infraction and $50,000 on any subsequent infraction for businesses that use, possess or acquire such software, and $10,000 rising to $100,000 for those who make it available. Criminal exposure runs to a fine of at least $10,000 and up to $500,000 with up to two years imprisonment on summary conviction, and at least $50,000 and up to $1 million with up to five years on indictment. The statutory text provides that a person does not have a defence by reason that they exercised due diligence to prevent the action from occurring. Widely circulating figures conflate the administrative and criminal regimes, and we set out the correct structure from CRA's own publication and the legislation.

A Note On Currency

Everything in this article is stated as verified in August 2026 and should be confirmed before reliance. Tax provisions are amended, administrative positions are reissued, and enforcement priorities change.

We have worked from the consolidated statutory text and from CRA's own publications wherever the point is legal, and from professional commentary and reporting where the point is operational. We say which is which throughout.

One methodological note specific to this subject. Several widely repeated accounts of the penalties in this area are wrong, not because their authors were careless but because two distinct regimes exist and are easily merged. We set out both and identify where the circulating figures come from.

This is not legal or tax advice. A business with any exposure in this area should obtain representation promptly, and the reasons for promptness are discussed at the end.

The Case That Prompted The Law

The origin of the current provisions, which is unusually well documented and worth understanding because it explains their severity.

A company in the business of developing and marketing point-of-sale programs for the restaurant and retail industry sold software to two restaurants. Commentary on the appellate judgment records that the court found the company's president sold the software to the restaurants knowing that the purchasers intended to use it to delete sales data and evade taxes[1].

The company was convicted of fraud. The conviction was overturned on appeal in R. v. InfoSpec Systems Inc., 2013 BCCA 333[1].

Reporting on the outcome records that the appellate court noted there was no evidence the software was ever used, and that in the court's view it had not been proven that the two restaurants actually used it to avoid paying taxes[2].

The court's reasoning, as reproduced in commentary, held that the law as it then stood did not criminalise the production, possession or sale of such software, and that the company participated in commercial transactions involving the sale of a computer program that was not prohibited by law, with the restaurants getting what they paid for[1].

We report the citation and the reasoning as they reach us through professional commentary and contemporaneous reporting, and note we have not read the judgment in full.

The Court's Invitation

The sentence that changed Canadian tax legislation, and the reason this history matters.

Commentary reproduces the court's closing observation: if Parliament considers a prohibition on such software necessary to thwart tax evasion, then it is open to it to enact a provision[1].

That is a court identifying a gap and declining to fill it judicially, which is an ordinary and proper exercise of restraint. It is also, in practice, an instruction.

The same commentary observes that Parliament seems to have anticipated this result, because the federal budget of March 2013 proposed both administrative monetary penalties and criminal sanctions for possession and acquisition of such devices[1].

The sequence is therefore compressed. The appellate decision and the budget proposal fall in the same year, and the resulting provisions took effect at the start of the following year.

Why this matters to an operator reading in 2026 is a point about drafting rather than history. Provisions written in direct response to a judicial finding that conduct fell outside the law are typically drafted to close the gap comprehensively, and the features described below are what comprehensive closure looks like.

Parliament's Response

The architecture, which is deliberately duplicated across two statutes.

Section 163.3 of the Income Tax Act and section 285.01 of the Excise Tax Act are parallel provisions. Each addresses electronic suppression of sales devices, and each cross-references the other[3][4].

Each contains three distinct penalty subsections addressing different conduct. Subsection (2) addresses a person who uses, or who knowingly or under circumstances attributable to neglect, carelessness or wilful default participates in, assents to or acquiesces in the use of, such a device or similar software in relation to records required to be kept[3].

Subsection (3) addresses a person who acquires or possesses such a device, or a right in respect of one, that is or is intended to be capable of being used in relation to required records[3][4].

Subsection (4) addresses a person who designs, develops, manufactures, possesses for sale, offers for sale, sells, transfers or otherwise makes available to another person, or who supplies installation, upgrade or maintenance services for, such a device[3][4].

Note the breadth of that third category. It captures not only the vendor but anyone providing installation, upgrade or maintenance services, which reaches the technician as well as the developer.

What Counts As Suppression

The scope question, which is wider than the popular understanding.

CRA describes electronic sales suppression software as selectively deleting or modifying sales transactions in point-of-sale systems, for example electronic cash registers, and in business accounting systems, leaving no record of the original transaction, with the result that tax on the income earned in those transactions is not reported or remitted[5].

A vendor of audit software describes CRA's own working definition more broadly still, stating that the Agency uses the term to cover zapper software, phantom-ware and manual voiding of transactions combined[6]. We report that as a commercial source's characterisation and have not verified it against internal CRA guidance.

If that characterisation is accurate it matters considerably, and this is our own analysis.

Popular understanding treats this subject as being about a discrete piece of illicit software installed deliberately. Phantom-ware is different: it refers to functionality built into an otherwise legitimate system, which may be dormant, undocumented, or presented as an ordinary feature.

And manual voiding is not software at all. It is a person using a normal function of a normal system in a particular pattern.

The practical consequence for an operator is that the question is not only whether anyone installed anything. It is whether the system in use has capabilities that were exercised, and whether the resulting pattern is explicable.

The Administrative Fines

The figures, taken from CRA's own publication because the secondary accounts conflict.

CRA states that following changes passed into law in January 2014, businesses that use, possess or acquire such software face fines of $5,000 on the first infraction and $50,000 on any subsequent infraction[5].

For the supply side, CRA states that anyone who manufactures, develops, sells, possesses for sale, offers for sale, or otherwise makes such software available faces $10,000 on the first infraction and $100,000 on any subsequent infraction[5].

The statutory text supports that escalation structure. The Excise Tax Act provision sets the higher amount at $50,000 where the action occurs after the Minister has assessed a penalty under that section or under the corresponding income tax section, and for the supply-side subsection sets $50,000 or, where the prior penalty was under the equivalent supply-side subsection, $100,000[4].

Two features of that drafting deserve emphasis and are our own reading.

The escalation is triggered by a prior assessment, not by a prior conviction. An administrative penalty assessed once places the taxpayer permanently in the higher tier for any subsequent action.

And the trigger crosses statutes. A penalty assessed under the income tax provision escalates the sales tax provision and vice versa, which is the subject of a section below.

The Criminal Provisions

The separate regime, which operates in addition to the fines above rather than instead of them.

CRA states that businesses or others who use, possess, acquire, manufacture, develop, sell, offer for sale or otherwise make available such software are subject to a fine of at least $10,000 and up to $500,000, or imprisonment for up to two years, or both, on summary conviction; and to a fine of at least $50,000 and up to $1 million, or imprisonment for up to five years, or both, if convicted of an indictable offence[5].

The statutory text confirms the summary conviction range. The Excise Tax Act offence provision provides that a person who commits the described acts, including supplying installation, upgrade or maintenance services, or who participates in, assents to or acquiesces in the commission of, or conspires with any person to commit, such an offence, is guilty of an offence and, in addition to any penalty otherwise provided, is liable on summary conviction to a fine of not less than $10,000 and not more than $500,000 or to imprisonment for a term not exceeding two years, or to both[7].

The phrase in addition to any penalty otherwise provided is the one to notice. The criminal fine is not an alternative to the administrative penalty; the statute contemplates both.

The minimum figures are also unusual. A fine of not less than $10,000 on summary conviction, and not less than $50,000 on indictment, removes judicial discretion below those floors.

For an operator the practical reading is that the exposure is layered: unremitted tax, interest, an administrative penalty, and on conviction a further fine with a statutory minimum.

Correcting The Circulating Figures

A section this article needs because the published accounts disagree, and a reader may well have encountered one of them.

Contemporaneous reporting at the time of the change stated that businesses or individuals caught using, developing or selling such software could face a fine of between $5,000 and $1 million, with a criminal conviction potentially resulting in a prison sentence of up to five years[8].

Other reporting from the same period stated that users could face fines up to $50,000 and jail time up to two years, while companies that make and sell the software face up to $100,000 and up to five years[2].

A summary reference work states that first infractions attract a $5,000 fine and subsequent infractions $50,000, that persons in possession could be fined up to $50,000, and developers or sellers up to $100,000[9].

None of these is a reliable statement of the position, and the reason is structural rather than a matter of any one source being careless.

There are two regimes. The administrative fines run $5,000 then $50,000 for the user side and $10,000 then $100,000 for the supply side. The criminal fines run from $10,000 to $500,000 on summary conviction and $50,000 to $1 million on indictment, with the prison terms attaching to the criminal regime only[5].

The circulating accounts take a number from one regime and pair it with a prison term or a maximum from the other. A reader who wants the correct structure should work from CRA's own tax alert and the statutory text rather than from summaries.

The Provision Nobody Expects

The feature that makes these provisions genuinely unusual in Canadian tax law.

The Excise Tax Act provision states that, except as otherwise provided in the following subsection, a person does not have a defence in relation to a penalty assessed under the section by reason that the person exercised due diligence to prevent the action from occurring[4].

That sentence removes the defence most Canadian taxpayers assume is always available.

Due diligence is the ordinary answer to an administrative penalty. A taxpayer who took reasonable care, relied on competent advice, and had systems in place to prevent the failure can generally resist a penalty on that basis, and the principle is well established across tax administration.

Here the legislation says so expressly and then excludes it, subject to whatever the following subsection preserves. We have not reproduced that exception because we have not verified its full terms, and an operator facing an assessment should have counsel read both subsections together.

The practical consequence for a restaurant owner is specific and uncomfortable, and this is our own analysis.

Consider an operator who bought a point-of-sale system in good faith, from a reputable vendor, and never knowingly used any suppression function. If that system is later determined to include a capability caught by the definition, the argument that the owner did not know and took reasonable care is, on the face of the provision, not a defence to the penalty for possession.

That inverts the ordinary risk allocation between a business and its technology supplier, and it is the strongest argument in this article for a specific and cheap precaution set out below.

Two Statutes, Cross-Referenced

The escalation mechanism, which compounds the exposure in a way the individual figures do not convey.

The income tax provision sets its higher penalty amount at $50,000 where the action occurs after the Minister has assessed a penalty payable under that section or section 285.01 of the Excise Tax Act[3]. The sales tax provision contains the mirror image, referring to a prior penalty under that section or section 163.3 of the Income Tax Act[4].

So the two regimes are not parallel tracks running independently. They are linked, and a penalty on either track escalates the other.

The supply-side subsection extends this further, distinguishing between a prior penalty under the use or possession subsections of either Act, which produces the $50,000 amount, and a prior penalty under the supply-side subsection of either Act, which produces $100,000[4].

The drafting therefore builds a ladder in which prior conduct of any described kind, penalised under either statute, moves the taxpayer permanently up a rung.

The relevant point for a restaurant is that suppressed sales create liabilities under both statutes anyway, because unreported restaurant revenue is both unreported income and unremitted sales tax. The two exposures are not alternatives to be argued between; they arise together from the same transactions.

One Assessment For Prior Conduct

A limiting provision that works in the taxpayer's favour, which is worth stating because this article is otherwise unrelieved.

The Excise Tax Act provision states that, despite the general assessment provision, if at any time the Minister assesses a penalty payable by a person under the section, the Minister is not to assess at or after that time another penalty payable by the person under the section in respect of an action of the person that occurred before that time[4].

The effect is that historic conduct is dealt with once. Having assessed, the Minister cannot return and assess again for actions predating the assessment.

That has a practical consequence for how a matter is handled, and this is our own reading. It means the exposure for past conduct is bounded at the point of assessment rather than accumulating per incident indefinitely, and it makes the identification of the relevant period important to both sides.

It does not, of course, protect conduct occurring after the assessment, which is precisely the conduct the escalated tier addresses.

Possession Is The Trigger

The element that operators most consistently misunderstand, and our own analysis of why it matters.

Read the possession subsection carefully. It applies to a person who acquires or possesses such a device, or a right in respect of one, that is or is intended to be capable of being used in relation to records required to be kept[3][4].

Three features follow from that wording.

The provision addresses acquisition and possession, which are states rather than acts. Nothing in it requires that the software was used.

The test attaches to capability. The words are capable of being used, not used.

And it extends to a right in respect of the device, which reaches a licence or an entitlement rather than requiring the code to sit on a machine the operator owns.

This is exactly the gap the appellate decision exposed. That court found there was no evidence the software had been used, and on the law as it then stood that was the end of the matter[2][1]. The provision Parliament enacted does not depend on use.

Combined with the express removal of the due diligence defence, the position for an operator is that possessing a capability they did not know they had and never exercised is, on the face of the legislation, within the penalty provision.

We would not overstate this. Whether and how the Agency applies the provision in such circumstances is a matter of administrative practice we cannot document, and any actual assessment would be contestable on facts we cannot anticipate. But the drafting is what it is, and the precaution it argues for costs almost nothing.

The Division That Reads Your Data

The audit capability, reported with appropriate caution about its source.

A vendor of audit-related software states that CRA has an Electronic Commerce Compliance Division with specialists trained to perform detailed point-of-sale analysis, and that raw data files are obtained from a taxpayer's computer database and cross-examined against official accounting records[6].

We report that as a commercial source's description, which we could not verify against a CRA publication, and note the source sells products in this area.

The described method is nonetheless consistent with the mechanism the legislation presupposes and worth understanding on that basis.

A modern point-of-sale system maintains more records than the reports it prints. Transaction logs, order modifications, voids, discounts, table transfers, staff sign-ons and system events are typically retained at a level below the summary reporting layer.

Suppression operates on the summary. The underlying log frequently retains evidence that a transaction existed, or that the record set is internally inconsistent, even where the sales total has been altered.

Commentary from the period describes operators using removable media so that a program could be removed from the computer without leaving a trace for an auditor to find[10], which we report as that source describes it.

The point that generalises for an operator is that the reports are not the records. A system's own database is the record, and it is the thing an examination reads.

The Winnipeg Cases

The outcomes on the ground, reported at second hand and flagged accordingly.

An academic article on sales suppression records that CRA announced it had found the relevant software in two Winnipeg restaurants, that both establishments entered guilty pleas, and that aggregate overdue taxes and fines amounting to $731,986 were imposed, with a portion of the fine specifically imposed for possession[11].

We report that figure as stated in a law review article citing contemporaneous news reporting, and we have not verified it against court records.

Two observations, both our own.

The aggregate figure combines overdue taxes and fines rather than separating them, which is how such outcomes are usually reported and which obscures the more useful number. For an operator assessing risk, the tax and interest component is generally the larger part and is owed regardless of any penalty outcome.

And the detail that a portion of the fine was imposed specifically for possession is consistent with the structure of the current provisions, in which possession is a distinct penalised state rather than merely evidence of use.

The same academic source makes an enforcement point worth relaying: that when such software becomes common in a community it becomes imperative to find the salesmen, installers and service providers who spread it, with the retailers being of secondary interest[11].

That is a description of enforcement strategy rather than of Canadian practice specifically, and it explains why the supply-side subsection reaches installation and maintenance services. It also implies something operators should sit with: an investigation of a vendor produces a customer list.

What The Auditor Actually Examines

Moving from the suppression provisions to the ordinary audit, which is what most restaurants will actually encounter. This section is our own analysis.

The great majority of restaurant audits involve no allegation of suppression at all. They involve indirect verification, because the sector's characteristics make direct verification of revenue difficult.

Those characteristics are worth naming plainly. High transaction volume at low individual values, a meaningful cash component, perishable inventory that is consumed rather than counted, and staff turnover that erodes institutional memory of how things were done.

The examination therefore concentrates on relationships that should hold if the reported revenue is complete.

Purchases against sales. Food and beverage purchased, adjusted for inventory movement and waste, implies a volume of product sold, which at menu prices implies revenue.

Cash against card. The proportion of sales settled in cash is relatively stable for a given concept and location, and a proportion materially below comparable operations invites a question about the cash that did not appear.

Labour against sales. Staffing is scheduled to expected volume. Hours worked that exceed what the reported revenue would require are a signal, and payroll records are hard to suppress because employees have their own copies and their own filings.

Occupancy and utilities. Rent, and particularly percentage rent clauses in a lease, and utility consumption, are third-party records proportional to activity.

The last of those is the restaurant equivalent of the materials argument from this publication's article on residential construction: inputs leave records with third parties even when sales do not.

The Food Cost Ratio

The single relationship that does most of the work in a restaurant audit, and the reason it is powerful.

Cost of goods as a percentage of sales is the sector's central operating statistic. Operators track it weekly because it governs the viability of the business, which means it is a figure the owner knows and the auditor can obtain.

Its usefulness in an examination follows from a simple property, and this is our own reasoning. If purchases are complete and sales are understated, the ratio rises. Understated revenue makes a restaurant look as though it is paying more for food relative to what it sells than it actually is.

The comparison can be made three ways, and an auditor will typically use all three: against the operation's own prior years, against published sector norms for the concept type, and against what the menu itself implies when priced out against recipe costs.

The third is the most demanding and the most difficult to argue with. Given a menu, a recipe or portioning standard, and purchase records, an examiner can construct an expected revenue figure directly.

Legitimate explanations for an elevated ratio exist in quantity and every experienced operator can list them: waste, spoilage, theft, staff meals, comped items, portion drift, promotional pricing, a change in menu mix, supplier price increases not passed through.

Each is a complete answer and each requires evidence. The operator who records waste, comps and staff meals contemporaneously has that evidence, and the operator who does not is asserting it.

Voids, No-Sales And The Audit Trail

The transactional pattern analysis, and why it reaches conduct short of software.

If CRA's working definition of suppression extends to manual voiding of transactions[6], then the void log is a document of interest independent of any software question.

Voids and no-sale drawer openings are ordinary in restaurant operation. Orders are entered incorrectly, customers change their minds, items are returned to the kitchen, and staff need to make change.

What an examination looks at is not the existence of these events but their distribution, and this is our own analysis of what such an analysis would reveal.

Concentration by staff member, by time of day, by shift, or by settlement type is the pattern that invites questions. Voids clustered at the end of a shift, or concentrated on cash transactions while card transactions are rarely voided, describe a pattern that ordinary error does not produce.

Volume relative to comparable operations is the second measure, and a rate materially above sector norms is a selection criterion.

Two management practices follow, and both have independent value as internal controls quite apart from tax.

Require a reason code and a supervisor authorisation for voids above a threshold, so the log carries an explanation rather than only an event. And review the void report periodically as a matter of routine, because an operator who has never looked at it cannot say whether its pattern is normal.

The Gross Negligence Penalty

The general penalty that sits behind all of this, quoted because its size is frequently underestimated.

Section 285 of the Excise Tax Act provides that every person who knowingly, or under circumstances amounting to gross negligence, makes or participates in, assents to or acquiesces in the making of a false statement or omission in a return, application, form, certificate, statement, invoice or answer made in respect of a reporting period or transaction is liable to a penalty of the greater of $250 and 25% of a computed amount[4].

We have not reproduced the computation formula and an operator should have it applied to their own facts rather than estimated.

The headline point is the rate. A penalty computed at 25% sits on top of the tax itself and the interest, and it is separate from anything under the suppression provisions.

The threshold is also worth noting precisely. The provision reaches conduct that is knowing or amounts to gross negligence, and it captures not only making a false statement but participating in, assenting to or acquiescing in one.

That last verb matters in a restaurant context. An owner who did not personally alter anything, but who was aware of how a manager handled cash and did not intervene, is within the language of acquiescence.

The parallel income tax penalty operates on the same principle. As with everything else in this article, the exposure is doubled by the two-statute structure.

Tips Are A Separate Exposure

An adjacent area this publication treats separately, flagged here because it arises from the same audit.

Gratuities in Canadian food service carry their own treatment questions, turning on whether amounts are controlled by the employer or paid directly, and those questions determine payroll and remittance obligations rather than sales reporting.

We have addressed restaurant and hospitality tip reporting separately and do not repeat that analysis here.

The reason it belongs in an audit article is that the two exposures are discovered together and are frequently confused by operators. A tip that flows through the point-of-sale system appears in the same transactional data an examiner reviews for sales completeness, and an operator explaining a cash pattern will find the two subjects interleaved.

The practical instruction is to be able to describe the tip arrangement precisely and consistently, in writing, before an examination rather than during one, because an inconsistent account of how gratuities are handled undermines credibility on the sales question as well.

What Records Survive

The documentation position, framed by every mechanism described above. This section is our own analysis.

The point-of-sale database, not just the reports. Retained for the full statutory retention period, in a form that can be produced. CRA states that businesses are responsible for maintaining adequate books and records, and that this includes proper records of all point-of-sale and accounting transactions[5].

Written confirmation from your system vendor. This is the precaution the possession provision and the removal of the due diligence defence jointly argue for, and it costs one email. Ask the vendor to confirm in writing that the system as supplied contains no functionality permitting deletion or modification of recorded sales transactions without an audit trail. Keep the answer.

A record of who has administrative access. Including any remote access retained by the vendor or an integrator, and any third party with the ability to modify system configuration.

Contemporaneous waste, comp and staff meal logs. These are the evidence for every legitimate explanation of an elevated cost ratio, and they cannot be reconstructed credibly.

Void reports, reviewed and initialled. A periodic review that leaves a trace demonstrates that the pattern was managed rather than ignored.

Inventory counts at period ends. Without them the cost ratio cannot be computed correctly, and an examiner will compute it anyway using assumptions the operator did not choose.

The unifying principle is the one from CRA's own guidance: the records requirement attaches to the transactions, not to the summaries a system happens to print.

What To Do

Get written vendor confirmation about suppression capability. The possession provision does not require use, and the legislation states that due diligence is not a defence. One email, kept on file.

Retain the point-of-sale database, not the reports. The database is the record. Confirm your retention arrangements cover it and that it can actually be produced.

Know your food cost ratio and be able to explain it. It is the relationship that does most of the work in an examination, and an elevated figure has many innocent explanations, all of which need evidence.

Log waste, comps and staff meals as they happen. These are that evidence. Reconstructed versions carry little weight.

Review the void report as routine. Require reason codes and supervisor authorisation above a threshold, and leave a trace of the review.

Count inventory at period ends. Otherwise the ratio will be computed on someone else's assumptions.

Document the tip arrangement in writing. Precisely and consistently, before rather than during an examination.

Understand that both statutes fire. Unreported restaurant revenue is unreported income and unremitted sales tax simultaneously, and the penalty provisions cross-reference each other.

If there is any exposure, get representation immediately. Relief mechanisms that depend on coming forward before the Agency acts are extinguished by an action the taxpayer cannot see.

The Limits Of This Analysis

Several caveats matter. This article is not legal or tax advice and no reader should act on it without professional guidance on their own facts; anyone with actual exposure under the provisions discussed should obtain representation rather than rely on a general description. Statutory text is quoted from published consolidations as verified in August 2026 and provisions are amended over time. We have described the due diligence exclusion and noted that it is expressed as subject to a following subsection whose terms we did not verify; counsel should read both together. We have not reproduced the penalty computation formula in the gross negligence provision. The judgment discussed is described through professional commentary and contemporaneous reporting rather than from the full text, and while the citation is corroborated by two independent sources we have not read the decision. The Winnipeg outcome figure reaches us through a law review article citing news reporting and was not verified against court records. The description of CRA's audit division and its data methods comes from a commercial vendor selling in this area and could not be verified against a CRA publication. The characterisation of CRA's working definition as extending to phantom-ware and manual voids comes from the same source and carries the same qualification. Contemporaneous news accounts of the penalty amounts conflict with each other and with CRA's own publication, and we have identified why rather than reconciling them. The audit examination areas, the ratio analysis, the void pattern reasoning, the vendor confirmation recommendation and the records analysis are our own. This article does not address provincial regimes including Quebec's mandatory billing requirements for the restaurant sector, liquor licensing, food safety, employment standards, or the detailed treatment of gratuities, which this publication treats separately.

Frequently Asked Questions

What are the actual penalties for sales suppression software?
Two separate regimes. Administrative fines of $5,000 on a first infraction and $50,000 subsequently for use, possession or acquisition; $10,000 rising to $100,000 for making it available. Criminal exposure of at least $10,000 up to $500,000 with up to two years on summary conviction, and at least $50,000 up to $1 million with up to five years on indictment. Circulating summaries mix the two.
Is due diligence a defence?
The legislation states that a person does not have a defence in relation to a penalty assessed under the section by reason that they exercised due diligence to prevent the action from occurring, subject to a following subsection. That removes the answer most taxpayers assume is available, and it is why written vendor confirmation about system capability is worth obtaining.
Do I have to have used the software?
The possession subsection addresses a person who acquires or possesses such a device, or a right in respect of one, that is or is intended to be capable of being used. Acquisition and possession are states, and the test attaches to capability rather than use. That is precisely the gap the 2013 appellate decision exposed, and the provision was drafted not to depend on use.
What does an ordinary restaurant audit look at?
Relationships that should hold if reported revenue is complete: purchases against sales, cash against card settlement proportions, labour hours against volume, and occupancy and utility costs. The food cost ratio does most of the work, because understated sales make the operation appear to pay more for food relative to what it sells than it actually does.
Can voids alone create a problem?
Potentially. One source describes CRA's working definition of suppression as covering zapper software, phantom-ware and manual voiding of transactions combined. If accurate, the void log is a document of interest independent of any software question, with concentration by staff member, shift or settlement type being the pattern that draws attention rather than the existence of voids.
Why does the two-statute structure matter?
Because unreported restaurant revenue is simultaneously unreported income and unremitted sales tax, so both regimes engage from the same transactions. The provisions also cross-reference: a penalty assessed under the income tax section escalates the sales tax section to its higher tier and vice versa, and the escalation is triggered by a prior assessment rather than a conviction.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article works from the statutory text and CRA's own publication to correct penalty figures that circulate incorrectly in three separate news and reference accounts. See References below.

References

  1. Thorsteinssons LLP Tax Blog. (2013, August 13). Criminal Fraud, Tax Evasion and the Electronic Suppression of Sales Data, on R. v. InfoSpec Systems Inc., 2013 BCCA 333, including the finding that the company's president sold the software knowing purchasers intended to use it to delete sales data and evade taxes, the absence of evidence that the software was used, the holding that the law as it then stood did not criminalise production, possession or sale, the quoted observation that it was open to Parliament to enact a provision, and the note that the March 2013 federal budget proposed administrative monetary penalties and criminal sanctions. Note: a Canadian tax law firm publication; we have not read the judgment in full. thor.ca
  2. Business in Vancouver. (2014, June 6). Businesses Using Tax Evasion Software Warned to Come Clean, on the January implementation of the new rules, the CRA press release warning of consequences, the 2012 fine imposed on a Richmond point-of-sale vendor and its overturning by the British Columbia Court of Appeal in 2013 on the basis that use by two Winnipeg restaurants had not been proven, and the reference to the voluntary disclosures programme. Note: contemporaneous business reporting; its penalty figures conflict with CRA's own publication as discussed in the text. biv.com
  3. Department of Justice Canada. Income Tax Act, RSC 1985, c. 1 (5th Supp.), section 163.3, consolidated text, for subsection (2) addressing use and participation, assent or acquiescence in use under circumstances attributable to neglect, carelessness or wilful default; subsection (3) addressing acquisition or possession of a device or a right in respect of one that is or is intended to be capable of being used; subsection (4) addressing design, development, manufacture, possession for sale, sale, transfer, making available and the supply of installation, upgrade or maintenance services; and the cross-reference to section 285.01 of the Excise Tax Act in setting the escalated amount. Note: primary legislation. laws-lois.justice.gc.ca — ITA s.163.3
  4. Department of Justice Canada. Excise Tax Act, RSC 1985, c. E-15, sections 285 and 285.01, consolidated text, for the gross negligence penalty of the greater of $250 and 25% of a computed amount in respect of false statements or omissions made knowingly or in circumstances amounting to gross negligence, including participation, assent or acquiescence; and for section 285.01 including the possession subsection, the supply-side subsection with its $50,000 and $100,000 tiers, the cross-reference to section 163.3 of the Income Tax Act, the limitation on assessing a further penalty in respect of actions occurring before an assessment, and the provision that a person does not have a defence by reason of having exercised due diligence, except as otherwise provided in the following subsection. Note: primary legislation. laws-lois.justice.gc.ca — ETA s.285.01
  5. Canada Revenue Agency. Electronic Suppression of Sales, tax alert, on the description of such software as selectively deleting or modifying sales transactions in point-of-sale and accounting systems leaving no record of the original transaction; the administrative fines of $5,000 on a first infraction and $50,000 on any subsequent infraction for use, possession or acquisition, and $10,000 rising to $100,000 for manufacture, development, sale or making available; the criminal penalties of at least $10,000 and up to $500,000 or imprisonment up to two years on summary conviction and at least $50,000 and up to $1 million or imprisonment up to five years on indictment; and the statement that businesses are responsible for maintaining adequate books and records including proper records of all point-of-sale and accounting transactions. Note: a CRA primary publication and the authoritative source for the penalty structure. canada.ca — Electronic Suppression of Sales
  6. Sales Data Controller. CRA — Canada, on the statement that CRA has an Electronic Commerce Compliance Division with specialists trained to perform detailed point-of-sale analysis, that the Agency uses the term electronic suppression of sales to cover zapper software, phantom-ware and manual voiding of transactions combined, and that raw data files are obtained from a taxpayer's computer database and cross-examined against official accounting records. Note: a commercial vendor of audit-related software; not verified against any CRA publication. salesdatacontroller.com
  7. Department of Justice Canada. Excise Tax Act, RSC 1985, c. E-15, offence provision, for the offence covering supply of installation, upgrade or maintenance services and participation, assent, acquiescence or conspiracy, and providing that a person is guilty of an offence and, in addition to any penalty otherwise provided, liable on summary conviction to a fine of not less than $10,000 and not more than $500,000 or to imprisonment for a term not exceeding two years, or to both. Note: primary legislation. laws-lois.justice.gc.ca — ETA offences
  8. CBC News. (2014, March 30). New Penalties Take Aim at Zapper Tax Evasion Software, on the federal government's stated rationale that such software undermines the competitiveness of businesses that abide by the rules, on the rules coming into force in January, and on a reported fine range and prison term. Note: contemporaneous news reporting; its penalty range conflates the administrative and criminal regimes as discussed in the text. cbc.ca
  9. Wikipedia. Automated Sales Suppression Device, on the general description of such software as falsifying electronic point-of-sale records, on point-of-sale records generally not being alterable by the operator and being used as the basis of tax assessments and audits, and on a summary of Canadian fine amounts. Note: a tertiary reference work; its Canadian figures are incomplete relative to CRA's publication and are cited only as an example of what circulates. en.wikipedia.org
  10. Al-Mulla CPAs. Electronic Sales Suppression Legislation in Canada, on the amendments to the Excise Tax Act and Income Tax Act effective 1 January 2014, on the use of removable media allowing a program to be removed without leaving a trace for an auditor, on the OECD 2013 report on electronic sales suppression as a threat to tax revenues, and on CRA's advice that taxpayers who may have interfered with a point-of-sale system consider coming forward before an investigation begins. Note: a professional services publication. almullacas.com
  11. Ainsworth, R. T. Sales Suppression: The International Dimension, American University Law Review, on the announcement that the software was found in two named Winnipeg restaurants, the guilty pleas entered, the aggregate overdue taxes and fines of $731,986, the note that a portion of the fine was specifically imposed for possession, and the enforcement observation that where such software becomes common it is imperative to find the salesmen, installers and service providers who spread it, with retailers being of secondary interest. Note: an academic article citing contemporaneous news reporting; the figure was not verified against court records. aulawreview.org

This article is provided for general informational purposes and is not legal or tax advice. Statutory provisions are quoted from published consolidations as verified in August 2026 and are amended over time. Several operational accounts are reported at second hand and are flagged where they could not be verified. Anyone with actual exposure under the provisions discussed should obtain professional representation rather than rely on a general description.