How to Respond to a PIPEDA Access Request: Step-by-Step Guide

Step-by-step guide to responding to a PIPEDA access request. Principle 9 requirements, 30-day timeline, identity verification, grounds for refusal, and OPC complaint avoidance.

Last updated: 2026-09-27

What PIPEDA Requires When Someone Asks for Their Data

Under PIPEDA, individuals have the right to access personal information that an organization holds about them. This right is established under Principle 9 — Individual Access — of Schedule 1 to the Act. When someone submits an access request, your organization must respond within 30 days with the information requested or a clear explanation of why the request was refused.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. Consult a qualified attorney for guidance specific to your business. The information here is based on PIPEDA and OPC guidance as of the date of publication.

Getting access requests right matters. The Office of the Privacy Commissioner of Canada (OPC) receives complaints when organizations fail to respond, respond late, or refuse without adequate justification. A complaint triggers an investigation that consumes significant time and resources. This guide walks through the process step by step so you can handle requests correctly and avoid OPC involvement entirely.

Principle 9: What It Actually Says

PIPEDA Principle 9 (Individual Access) states that upon request, an individual shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information. The individual must be able to challenge the accuracy and completeness of the information and have it amended as appropriate.

Specifically, an organization must:

  • Respond to a request within 30 days of receiving it
  • Provide the information in a generally understandable form
  • Explain any abbreviations or codes used
  • Inform the individual of the use and disclosure of the information
  • Provide the individual with an account of third parties to which the information has been disclosed

The information must be provided at a minimal or no cost to the individual. The OPC has been clear that costs should not create a barrier to exercising the right of access.

Step-by-Step: Responding to a PIPEDA Access Request

Step 1: Recognize and Log the Request

An access request under PIPEDA does not need to be in a specific form. The individual does not need to cite PIPEDA or use any particular wording. If someone asks your organization what personal information you hold about them, that is an access request.

When a request arrives:

  • Record the date received. Your 30-day clock starts immediately.
  • Note the channel. Email, phone, letter, web form, in person — all are valid.
  • Capture the requester's identifying details. Name, email, account number, or whatever information they provide.
  • Assign responsibility. Someone specific needs to own this request through to completion.

Send an acknowledgment to the requester promptly. This is not a PIPEDA requirement, but it is good practice. It confirms you received the request, sets expectations for the timeline, and establishes a communication trail.

Step 2: Verify the Requester's Identity

Before disclosing personal information, you must be satisfied that the person making the request is who they claim to be. Disclosing someone's personal information to the wrong person is a breach — and an entirely preventable one.

The level of verification should be proportionate to the sensitivity of the data:

Low-sensitivity situations: If a customer emails from the address on file and asks about their account data, the existing relationship provides reasonable assurance of identity.

Moderate-sensitivity situations: Ask the requester to confirm two or more pieces of information you can match against your records — account number, date of birth, recent transaction details, or the last four digits of a phone number.

High-sensitivity situations (health data, financial data, or requests by third parties): Request government-issued photo ID. If someone is making a request on behalf of another person, require written authorization (a signed letter, power of attorney, or equivalent).

Do not use verification as a delay tactic. The OPC views disproportionate or unnecessary identity verification as an obstruction of the access right. Ask for what you need and nothing more.

Step 3: Search Your Systems

Search every system where the requester's personal information might be held. This includes:

  • Customer relationship management (CRM) systems
  • Email marketing platforms
  • Customer support tools and ticketing systems
  • Accounting and invoicing software
  • Email inboxes (search for the requester's name and email)
  • Cloud storage and shared drives
  • Spreadsheets and databases
  • Paper records and physical files
  • Any third-party tools where personal information may be stored

Use a consistent search checklist so that every request is handled the same way. For guidance on building a data search process, see our data mapping guide.

Step 4: Compile and Review the Information

Once you have gathered the personal information, review it before sending:

Format it clearly. PIPEDA requires that information be provided in a "generally understandable form." Do not send raw database exports with cryptic field names. Organize the data in a clear, readable format — a structured document or clearly labeled spreadsheet.

Explain codes and abbreviations. If your systems use internal codes (customer status codes, product SKUs referenced in transaction records, etc.), provide a legend or translate them into plain language.

Check for third-party information. Your records may contain personal information about other individuals (for example, a support ticket that mentions another customer). You should not disclose another person's personal information without their consent. Redact third-party personal information from the records you provide.

Document the use and disclosure. Prepare an explanation of how the requester's personal information has been used and to whom it has been disclosed. This is a specific requirement under Principle 9 that organizations often overlook.

Step 5: Assess Whether Any Refusal Grounds Apply

PIPEDA Section 9(3) sets out circumstances where an organization may refuse access to personal information. The grounds include:

  • Information that would reveal personal information about another individual (unless the other individual consents or the individual is in a life-threatening situation)
  • Information that cannot be disclosed for legal, security, or commercial proprietary reasons
  • Information that is protected by solicitor-client privilege or the professional secrecy of advocates and notaries
  • Information generated in the course of a formal dispute resolution process
  • Information that would compromise the confidentiality of commercial information that cannot be separated from the requested information

Additionally, Section 9(3.1) provides that an organization is not required to provide access if doing so could reasonably be expected to threaten the life or security of another individual.

If you rely on any refusal ground, you must:

  1. Inform the requester that you are refusing (or partially refusing) the request
  2. State the specific reason for the refusal
  3. Cite the relevant provision of PIPEDA
  4. Inform the requester of their right to complain to the OPC

Partial refusals are common. If only some of the information is subject to a refusal ground, you must still provide the remainder.

Step 6: Respond Within 30 Days

Your response must be sent within 30 days of receiving the request. The response should include:

If providing the information:

  • The personal information found, organized in a clear and understandable format
  • An explanation of how the information has been used
  • An account of any third parties to whom the information has been disclosed
  • Information about the individual's right to challenge accuracy and request corrections

If refusing (in whole or in part):

  • A clear statement of what is being refused
  • The specific ground for refusal under Section 9(3)
  • The individual's right to file a complaint with the OPC

If you need more time: PIPEDA permits extensions in limited circumstances — for example, where meeting the 30-day deadline would unreasonably interfere with the organization's activities, or where additional time is needed for consultation. If you need an extension, you must notify the requester within the initial 30-day period and provide a revised timeline. Extensions should be the exception, not the default.

Step 7: Deliver Securely

Personal information must be delivered securely. Options include:

  • Password-protected files sent by email, with the password communicated through a separate channel
  • Secure file-sharing links with access controls and expiration dates
  • Encrypted email if your systems support it
  • Physical mail using tracked delivery for paper records

Do not send personal information as an unprotected email attachment.

Step 8: Record Everything

Maintain a record of how the request was handled, including:

  • The original request and the date received
  • Identity verification steps taken
  • Systems searched and results
  • Any refusal grounds considered or applied
  • The response sent and the date
  • Any correspondence with the requester

These records protect you if a complaint is later filed with the OPC. See our DSAR record keeping guide for detailed guidance.

Avoiding OPC Complaints

Most OPC complaints about access requests arise from a small number of recurring problems:

Not responding at all. The most common complaint. Even if a request is complex, acknowledge it and communicate proactively.

Responding late. The 30-day deadline is not a suggestion. Track your deadlines rigorously.

Providing incomplete information. Search all your systems, not just the obvious ones. Individuals often know (or suspect) that you hold more data than what you provide.

Refusing without adequate explanation. If you refuse a request, cite the specific PIPEDA provision and explain the reason clearly. A vague refusal invites a complaint.

Creating barriers to access. Excessive identity verification requirements, unreasonable fees, or complicated procedures that discourage individuals from pursuing their requests will attract OPC scrutiny.

Not informing the individual of their rights. When refusing a request, you must tell the individual they can complain to the OPC. Omitting this is itself a deficiency.

After the Response: Corrections and Challenges

Under Principle 9, individuals have the right to challenge the accuracy and completeness of their personal information and have it amended. If a requester contacts you after receiving their data and says something is wrong, you must:

  1. Investigate the challenged information
  2. Correct, delete, or annotate the information if the challenge is justified
  3. Notify third parties who have received the incorrect information
  4. Inform the requester of the outcome

If you disagree with the challenge, you must record the individual's objection and note the unresolved disagreement in your records. Individuals dissatisfied with the outcome can complain to the OPC.

Related Guides

References

Last reviewed: September 2026. Privacy laws change frequently. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.