Consent Withdrawal Under PIPEDA: How to Handle Data Deletion Requests in Canada
Step-by-step guide to processing consent withdrawal and data deletion requests under PIPEDA and Law 25. Timelines, exceptions, and compliance procedures.
Consent withdrawal is one of the most fundamental privacy rights in Canada—and one of the most operationally challenging to implement. When a customer says "stop using my data," your organization needs clear procedures to respond correctly and within legal timelines.
The Right to Withdraw Consent
PIPEDA Framework
PIPEDA Principle 3 (Consent), clause 4.3.8 of Schedule 1, states:
"An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. The organization shall inform the individual of the implications of such withdrawal."
Key Points:
- Organizations must inform individuals of implications
- Cannot be punitive (no unreasonable penalties for withdrawal)
- Must be processed promptly
Quebec Law 25
Law 25 strengthens withdrawal rights:
- Individuals must be informed, when information is collected, of their right to withdraw consent to its communication or use (s. 8)
- Requests for rectification, including where keeping the information is not authorized by law, must be answered in writing within 30 days (ss. 28, 32)
- Right to require cessation of dissemination or de-indexing of a hyperlink in certain circumstances (s. 28.1)
CPPA (Proposed in Bill C-27, Never Enacted)
Bill C-27 died on the Order Paper in January 2025, so the Consumer Privacy Protection Act never became law. Its first-reading text would have required an organization, on an individual's written request, to dispose of their personal information as soon as feasible in certain circumstances, including where the individual had withdrawn consent (CPPA s. 55, bill text).
Types of Consent Withdrawal Requests
1. Marketing Opt-Out
Most Common: "Stop sending me emails/calls"
Requirements:
- Process within 10 business days (CASL)
- Remove from all marketing lists
- Don't need to delete all data
- Continue transactional communications
- Document the opt-out
2. Service-Related Withdrawal
"Stop using my data for [specific purpose]"
Requirements:
- Assess what data is affected
- Inform individual of service implications
- Process partial withdrawal where possible
- Document the request and response
3. Full Consent Withdrawal
"Delete all my data"
Requirements:
- Broadest request — affects all processing activities
- Must retain data required by law
- Must inform individual of what cannot be deleted and why
- Process promptly (in Quebec, rectification requests must be answered within 30 days)
- Extend to third parties
Step-by-Step Withdrawal Process
Step 1: Receive and Log the Request
Acceptable Request Channels:
- Email to privacy officer
- Online form/portal
- Phone (follow up with written confirmation)
- In-person (document the request)
- Through platform unsubscribe mechanism
What to Record:
- Date and time of request
- Individual's identity and contact information
- Scope of withdrawal (specific or complete)
- Channel received through
- Assigned handler
Step 2: Verify Identity
Before processing, verify the requester's identity:
- Match against account information
- Don't require excessive identification
- Use existing authentication where possible
- If unable to verify, request minimal additional proof
- Document verification method
Important: Don't collect more personal information than necessary to verify identity.
Step 3: Assess Scope and Implications
Determine:
- What personal information is affected
- What processing activities must stop
- What data must be retained (legal obligations)
- Impact on services provided to the individual
- Third parties who must be notified
Step 4: Inform the Individual
Before processing, inform the individual of:
- What will happen to their data
- What services they'll lose access to
- What data must be retained and why (legal obligations)
- Timeline for processing
- Their right to change their mind (within processing period)
Step 5: Process the Withdrawal
Stop Processing:
- Remove from marketing lists
- Disable data analytics using their data
- Stop sharing with third parties
- Deactivate account if applicable
- Remove from automated decision-making
Delete Data:
- Remove from active databases
- Schedule backup deletion
- Clear from caches
- Remove from analytics systems
- Archive minimum necessary for legal obligations
Notify Third Parties:
- Inform all recipients of the data
- Request confirmation of deletion
- Document notifications and responses
Step 6: Confirm Completion
Promptly (and within 30 days where Quebec's s. 32 applies), send confirmation including:
- What data was deleted
- What data was retained (and legal basis)
- What processing has stopped
- Third parties notified
- Contact for further questions
Legal Exceptions to Deletion
When You Can Retain Data Despite Withdrawal
| Reason | Legal Basis | Retention Period |
|---|---|---|
| Tax records | Income Tax Act, s. 230(4) | Generally 6 years from end of last tax year the records relate to |
| Financial transactions (reporting entities) | Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, s. 148 | At least 5 years |
| Employment records | Employment standards | Varies by province |
| Legal proceedings | Court orders, litigation | Duration of proceedings |
| Regulatory requirements | Industry-specific laws | As required |
| Contractual obligations | Active contracts | Duration of contract |
How to Handle Exceptions
- Delete everything you can
- Clearly explain what you're retaining and why
- Minimize retained data to what's legally required
- Increase security for retained data
- Set calendar reminders to delete when retention period ends
- Don't use retained data for any other purpose
CASL Unsubscribe Requirements
Timeline: 10 Business Days
CASL is specific about unsubscribe processing:
- 10 business days to process unsubscribe requests
- Must be operational for 60 days after sending
- Must be available at no cost to the recipient (s. 11(1))
Unsubscribe Mechanism Requirements
- Clear and prominent in every CEM, and able to be readily performed (Electronic Commerce Protection Regulations (CRTC), s. 3)
- One-click or simple process preferred
- Working link (test regularly)
Building a Withdrawal Management System
Minimum Viable Process (Small Business)
- Dedicated email — privacy@yourcompany.ca
- Request tracking spreadsheet — Date, requester, scope, status, completion date
- Checklist template — Standard steps for each withdrawal type
- Confirmation email template — What was done
- Third-party notification template — Inform partners
Automated Process (Growing Business)
- Self-service portal — Customers submit and track requests
- Automated workflows — Route requests to appropriate handlers
- Integration with systems — Automatic deletion from CRM, email, analytics
- Compliance dashboard — Track SLA compliance (e.g. Quebec's 30-day response deadline)
- Audit trail — Automatic documentation of all actions
Common Mistakes
1. Making Withdrawal Difficult
Don't require customers to call, visit, or jump through hoops. Withdrawal should be as easy as giving consent.
2. Delayed Processing
Where a 30-day deadline applies (such as Quebec's s. 32), treat it as the maximum, not the target. Process requests as quickly as possible.
3. Ignoring Third Parties
You must notify all parties who received the individual's data. This includes vendors, partners, and advertisers.
4. Punitive Responses
Don't charge fees, reduce service quality, or retaliate against individuals who withdraw consent. This violates PIPEDA principles.
5. Incomplete Deletion
Check all systems: primary database, backups, caches, analytics, CRM, email lists, third-party integrations. Partial deletion = non-compliance.
Frequently Asked Questions
Q: Can a customer withdraw consent but keep their account? It depends on what data processing is essential for the account. You can maintain the account with reduced functionality if some data processing is withdrawn.
Q: What if I need the data for a legal claim? You can retain data necessary for legal proceedings. Document the legal basis and delete once proceedings conclude.
Q: Can I ask why someone is withdrawing consent? You can ask, but you should not require an explanation. Under PIPEDA clause 4.3.8, an individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
Q: Does withdrawal have to be in writing? No. Verbal withdrawal is valid, but best practice is to confirm in writing for documentation purposes.
Q: What if withdrawal would breach a contract? Inform the individual of contractual implications. They may need to terminate the contract, but you cannot prevent withdrawal of consent.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Related Articles:
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Social Media Privacy Compliance Canada: Business Account Management Guide 2026
Social media and Canadian privacy law: what PIPEDA, CASL and Law 25 require of business accounts, ad...
Remote Work Privacy Canada: BYOD, VPN & Employee Monitoring Compliance Guide 2026
Remote work privacy in Canada: BYOD, VPNs, lawful employee monitoring and home-office data security ...