One day an email arrives: "Please send me all the personal information you have about me," or "I want you to delete my data." It might come from a customer, a former employee, or someone who is annoyed with you. Under Canadian privacy law, they are usually within their rights, and you are usually required to respond, properly and on a clock. Most small businesses freeze at this point. You do not need to. Handled with a simple process, one of these requests is routine, not a crisis.
The rights you are dealing with
Canadian privacy laws give individuals a few related rights over their own personal information. The main ones you will meet:
- Access: the right to ask what personal information you hold about them, how you use it, and who you have shared it with.
- Correction: the right to have inaccurate information fixed.
- Deletion and withdrawal of consent: the right to withdraw consent and, especially under Quebec's Law 25, to have information deleted or de-indexed in many cases.
The exact wording and limits differ across PIPEDA, Quebec's Law 25, and the federal reform working its way through Parliament, so treat this as a practical orientation rather than legal advice. The core duty, though, is consistent: take the request seriously and respond.
When a request is valid
Two things matter more than formality. First, the request does not need special legal language: a plain email saying "send me my data" counts, and you cannot ignore it because they did not fill in a form. Second, you must confirm who is asking. Handing someone's personal data to an imposter is itself a privacy breach, so verify identity before you release anything, using information you already hold, not by demanding a pile of new documents you do not need.
What you must do, and how fast
Once a valid request is in, the clock starts. Under PIPEDA you generally have 30 days to respond, and Law 25 works on a similar timeline. You should provide the information in a form the person can actually understand, and in most cases you cannot charge for it, or only a minimal cost. If you are going to say no, in whole or in part, you generally have to tell them why and let them know they can complain to the relevant privacy regulator. Silence is the one response that is never acceptable.
When you can say no, or not fully
The rights are strong, but not unlimited. Common, legitimate reasons to withhold or limit what you provide or delete:
- Someone else's information. If the records are tangled up with another person's personal data, you may need to redact rather than hand it all over.
- Legal retention duties. You cannot delete what the law requires you to keep, tax and financial records being the obvious example. Deletion is not absolute.
- Legal privilege or specific exemptions defined in the applicable law.
The rule of thumb: lean toward giving people what they ask for, and when you must refuse, refuse narrowly and explain it. Knowing what you are keeping, and why, is where a retention stance pays off.
Build a simple process now, not under pressure
The difference between a scramble and a routine is a little preparation:
- Name an owner. Your Privacy Officer (in a small shop, often the owner) handles these.
- Give it a front door. A monitored address like privacy@yourcompany.ca so a request cannot sit unseen in someone's inbox.
- Know where personal data lives. You cannot fulfill an access or deletion request if you do not know what you hold and where. That is the everyday value of a light data inventory.
- Keep a simple log. Note each request, what you did, and when. If a regulator ever asks, that record is your proof you took it seriously.