PIPEDA Access Requests: How to Respond Within 30 Days
How to handle a PIPEDA access request: the 30-day clock, what you must provide, the limited exceptions, and how to document your response.
One of PIPEDA's most operationally important obligations is the individual right of access. Any person whose personal information you hold can ask to see it — and you have 30 days to respond. Access was the most common type of PIPEDA complaint the OPC accepted in 2023-2024 (101 of 446 complaints, or 23%, according to the OPC's 2023-2024 annual report). Here's how to get it right.
Last updated: April 2026
The Right of Access Under PIPEDA
PIPEDA Principle 9 (Individual Access) gives individuals the right to:
- Know what personal information you hold about them
- Access that information (receive a copy or meaningful description)
- Know how it has been used
- Know to whom it has been disclosed
- Challenge the accuracy of their information
This right is fundamental to PIPEDA's consent-based model. Individuals can only meaningfully consent to data use if they can verify what data you hold and how it's being used.
Who Can Make an Access Request?
Any individual whose personal information you hold can make an access request. This includes:
- Current and former customers
- Website visitors (if you have identifiable data about them)
- Current and former employees (PIPEDA covers employee information only for federally regulated employers)
- Prospective customers whose data you collected during a sales process
- Third parties whose information you collected incidentally (though access rights for third parties are more limited)
There is no fee requirement — PIPEDA requires responses at minimal or no cost (Schedule 1, clause 4.9.4), and an organisation may charge only if it first tells the individual the approximate cost and the individual confirms they are not withdrawing the request (s. 8(6)).
The 30-Day Response Deadline
You have 30 calendar days from receiving the request to provide a response. This is a hard deadline.
What counts as "receiving" the request? Any written request, regardless of how it's delivered (email, postal mail, web form, social media message). PIPEDA requires access requests to be made in writing (s. 8(1)), so verbal requests should be confirmed in writing to start the clock.
Can you extend the deadline? Yes — PIPEDA s. 8(4) allows an extension of up to 30 additional days if:
- Meeting the original deadline would unreasonably interfere with your activities
- The time needed for consultations necessary to respond would make meeting the deadline impracticable
It also allows an extension for the period needed to convert the information into an alternative format.
No later than 30 days after the request, you must send the requester a notice of extension setting out the new time limit, the reasons for the extension, and their right to complain to the Commissioner about it.
What happens if you miss the deadline? Missing the deadline is a PIPEDA violation. The individual can complain to the OPC, who may investigate and publish findings against your organisation.
What Information Must You Provide?
When responding to an access request, you must provide:
1. The Personal Information Itself
Provide a copy of the personal information, or a description of it that allows the individual to understand what you hold. You can provide:
- Copies of documents
- A structured data export
- A written summary
- A combination of the above
Format: The information should be provided in an intelligible form. If data is in coded format, provide a key or explanation.
2. Information About Uses
Explain how the personal information has been used or is currently being used — what purposes it serves.
3. Information About Disclosures
Provide information about any third parties to whom the information has been disclosed. Note: you don't necessarily have to name the third party if there are legitimate confidentiality reasons — you can describe the category (e.g., "our payment processor" or "our marketing service provider").
What You Can Withhold
PIPEDA contains several exceptions that allow organisations to refuse access to certain information:
1. Third Party Information
You must not give access if doing so would likely reveal personal information about a third party, unless the third party consents or the information is needed because someone's life, health or security is threatened (s. 9(1)–(2)). If the third-party information is severable, sever it and give access to the rest.
2. Solicitor-Client Privilege
Information protected by solicitor-client privilege (or the professional secrecy of advocates and notaries) or by litigation privilege can be withheld (s. 9(3)(a)).
3. Confidential Commercial Information
Information can be withheld if giving access would reveal confidential commercial information, but you must sever it and provide the rest where it is severable (s. 9(3)(b)).
4. Investigations and Government Disclosures
Information collected without consent under s. 7(1)(b) (for investigating a breach of an agreement or a contravention of law) need not be disclosed (s. 9(3)(c.1)). Requests about disclosures to government institutions, for example for law enforcement or national security, follow a separate notification process under s. 9(2.1)–(2.4).
5. Information You Don't Actually Have
You are not obligated to create records that don't exist. If you don't hold personal information about the individual, say so clearly.
Step-by-Step Access Request Response Process
Step 1: Acknowledge Receipt
Send an acknowledgment within 24-48 hours confirming you received the request and the expected response date.
Template acknowledgment:
"Thank you for your access request received on [date]. Under PIPEDA, we will respond within 30 days (by [date]). We may contact you to verify your identity before releasing personal information."
Step 2: Verify Identity
Before releasing personal information, verify the requester's identity. You don't want to disclose personal information to an impersonator.
Appropriate verification:
- Ask for information the individual should know (account details, purchase history)
- Request a government-issued ID (last resort — only ask for this if truly necessary, and don't retain a copy)
Caution: Don't make identity verification so burdensome that it becomes a de facto barrier to access.
Step 3: Locate the Information
Search all your systems for personal information about the individual:
- CRM and customer database
- Email communications
- Billing and financial records
- Support tickets and correspondence
- Marketing databases
- Analytics data (if tied to an identifiable individual)
- Backup systems (if reasonably accessible)
Document your search process — this is important if the OPC ever reviews your response.
Step 4: Review and Apply Exceptions
Review the information found and determine:
- What must be provided
- What can/must be withheld (with legal justification)
- What requires severing third party information
Step 5: Prepare the Response
Compile the response package:
- Cover letter explaining what is included, what is withheld and why
- Copies or descriptions of personal information
- Explanation of how information has been used and disclosed
Step 6: Send the Response
Deliver securely — don't email sensitive personal information without encryption. Options:
- Secure email
- Password-protected PDF
- Secure file transfer
- Postal mail
Corrections and Challenges
After receiving the access response, individuals may:
- Challenge the accuracy of their information
- Request corrections to inaccurate or incomplete data
If the individual successfully demonstrates an error, you must amend the record and, where appropriate, transmit the amended information to third parties with access to it (Schedule 1, clause 4.9.5).
If the challenge is not resolved to the individual's satisfaction, you must record the substance of the unresolved challenge and, when appropriate, inform third parties with access to the information that it exists (clause 4.9.6).
Common Mistakes in Handling Access Requests
Mistake 1: Ignoring requests Any written communication asking to see personal information should be treated as an access request — even if it doesn't use PIPEDA terminology.
Mistake 2: Searching only obvious systems Don't forget email archives, accounting systems, legacy databases, and backup servers. A thorough search is required.
Mistake 3: Over-withholding Organisations often withhold too much information citing vague exceptions. The OPC will scrutinise unjustified refusals.
Mistake 4: Collecting excessive verification information Asking for a notarised document or multiple pieces of government ID to verify identity is usually disproportionate.
Mistake 5: Charging fees as a barrier PIPEDA requires responses at minimal or no cost; any fee must be disclosed to the individual in advance.
Provincial Differences
| Province | Law | Access Deadline |
|---|---|---|
| Ontario | PIPEDA | 30 days (s. 8(3)) |
| Quebec | Private sector Act (as amended by Law 25) | 30 days after receipt (s. 32) |
| Alberta | PIPA | 45 days (s. 28) |
| BC | PIPA | 30 days, where "day" excludes Saturdays and holidays (s. 29) |
Note: For healthcare, PHIPA in Ontario and HIA in Alberta impose separate access obligations.
Frequently Asked Questions
Q: Does our access request obligation apply to former customers? A: Yes — you must respond to access requests from former customers as long as you still hold their personal information.
Q: What if we've already deleted the information? A: Tell the requester that you no longer hold their personal information and explain when and how it was deleted. Document this.
Q: Can we charge for responding to access requests? A: PIPEDA requires responses at minimal or no cost. You may charge only if you first inform the individual of the approximate cost and they confirm they are not withdrawing the request (s. 8(6)).
Q: What if we suspect the access request is being made by a competitor to understand our customer base? A: PIPEDA doesn't allow you to deny access based on motive. However, identity verification is permitted — confirm the requester is actually the individual they claim to be.
Streamline Your Access Request Handling
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — privacy compliance without the paperwork burden.
Related reading: PIPEDA Compliance Guide | What is Personal Information Under PIPEDA | PIPEDA Fines and Penalties
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
What Personal Information Does PIPEDA Protect? Complete Guide
What counts as personal information under PIPEDA, what does not, how sensitive information is treate...
CPPA vs PIPEDA: What Bill C-27 Proposed, and Why PIPEDA Still Applies
The Consumer Privacy Protection Act (CPPA) was proposed in Bill C-27, which died in January 2025 and...