Right to Be Forgotten in Canada: Data Deletion Rights Under PIPEDA and Law 25
Complete guide to data deletion and de-indexing rights in Canada. Learn how PIPEDA and Law 25 handle erasure requests, and what the never-enacted CPPA proposed.
The "right to be forgotten" is evolving rapidly in Canada. While PIPEDA doesn't explicitly include a GDPR-style right to erasure, Quebec's Law 25 has established robust data deletion rights for Quebecers. (The CPPA proposed in Bill C-27 would have added federal deletion rights, but it never became law.)
Current State of Data Deletion in Canada
PIPEDA's Approach
PIPEDA provides indirect deletion rights through several principles:
Principle 5 — Limiting Use, Disclosure, and Retention: Personal information shall be retained only as long as necessary for the fulfillment of those purposes.
Principle 9 — Individual Access: Upon request, individuals shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information.
OPC Interpretation: The OPC has consistently held that once the purpose for collection has been fulfilled and there's no legal retention requirement, individuals can request deletion.
Quebec Law 25: Explicit Deletion and De-indexing Rights
Law 25 creates Canada's first explicit "right to be forgotten" with two components:
1. Right to Deletion (Article 28.1)
- Right to have personal information deleted when:
- Collection was unlawful
- Purpose has been fulfilled
- Consent has been withdrawn
- Retention period has expired
2. Right to De-indexing (Article 28.1)
- Right to have personal information de-indexed from search engines when:
- Information causes serious harm
- Dissemination violates law or court order
- Information is no longer relevant to the original purpose
CPPA (Bill C-27, Never Enacted): Proposed Deletion Rights
Bill C-27 died on the Order Paper in January 2025, so the CPPA never became law. Its first-reading text would have required an organization, on an individual's written request, to dispose of their personal information as soon as feasible in certain circumstances, including where the individual had withdrawn consent (CPPA s. 55, bill text).
How to Handle Deletion Requests
Step 1: Verify the Requester's Identity
Before processing any deletion request:
- Confirm the individual's identity
- Don't require excessive identification
- Use existing authentication methods where possible
- Document the verification process
Step 2: Assess the Request
Determine whether you must comply:
You MUST delete when:
- Consent has been withdrawn and no other legal basis exists
- The purpose for collection has been fulfilled
- Data was collected unlawfully
- Retention period has expired
- A court or regulatory order requires deletion
You MAY refuse when:
- Legal retention obligations exist (tax, financial regulations)
- Data is needed for ongoing legal proceedings
- Public interest justification exists
- Journalistic, artistic, or literary purposes
- Archival purposes in the public interest
Step 3: Process the Deletion
Internal Systems:
- Delete from primary databases
- Remove from backups (where feasible)
- Clear from cache systems
- Remove from analytics and reporting
- Delete from employee systems
Third Parties:
- Notify all third parties who received the data
- Request confirmation of deletion
- Document the notification and responses
Step 4: Confirm Completion
- Notify the requester within 30 days (PIPEDA) or Law 25 timelines
- Provide confirmation of what was deleted
- Explain any data that could not be deleted (and why)
- Keep a record of the request and actions taken (without keeping the deleted data)
De-indexing Requests Under Law 25
How De-indexing Works
De-indexing is distinct from deletion—it removes information from search engine results without necessarily deleting the source:
- Individual submits request to the organization
- Organization assesses whether criteria are met
- If valid, organization contacts search engines
- Search engines remove the URLs from results
- Source pages may still exist but won't appear in searches
Criteria for De-indexing
Law 25 requires de-indexing when information:
- Causes serious injury to the individual
- Violates the law or a court order
- Is no longer necessary for the original purpose
- Does not serve the public interest
Balancing Test
Organizations must balance:
- Individual's privacy rights
- Public interest in the information
- Freedom of expression
- Historical/archival value
- Journalistic purposes
Technical Implementation
Building a Deletion Workflow
1. Request Intake
- Web form for deletion requests
- Email address for privacy requests
- Telephone option
- Track all requests in a central system
2. Data Discovery
- Automated search across all systems
- Check all databases, backups, archives
- Third-party data sharing records
- Employee who processed the data
3. Deletion Execution
- Automated deletion scripts where possible
- Manual deletion for unstructured data
- Backup retention policies
- Cache invalidation
4. Verification
- Confirm deletion across all systems
- Third-party confirmation
- Audit trail
- Quality assurance check
Handling Backups
One of the most challenging aspects of data deletion:
Option 1: Delete from backups immediately
- Most compliant approach
- Technically complex and expensive
- May affect backup integrity
Option 2: Encrypt and schedule deletion
- Mark data for deletion in next backup cycle
- Encrypt in interim
- Ensure data isn't restored during normal recovery
Option 3: Documentation approach
- Document the deletion request
- Delete from active systems immediately
- Delete from backups per retention schedule
- Ensure data isn't restored from backups
OPC Guidance: The OPC has accepted that backup deletion may follow a reasonable schedule, but active systems must be cleaned immediately.
Industry-Specific Considerations
Financial Services
- Tax records: 7-year retention requirement
- Anti-money laundering: 5-year retention after account closure
- Investment records: 7+ year retention
- Partial deletion permitted: Delete what you can, retain what you must
Healthcare
- Patient records: 10+ years in most provinces
- Medical imaging: Varies by province
- Mental health records: Enhanced protections
- Cannot delete most health records during retention period
E-Commerce
- Transaction records: 7 years (tax purposes)
- Customer profiles: Delete upon request
- Marketing data: Delete immediately upon request
- Reviews and ratings: Complex—may be anonymized instead
HR/Employment
- Personnel files: 2-7 years post-employment
- Payroll records: 7 years
- Applications (rejected): 6 months recommended
- Reference checks: Delete once hiring decision made
Response Timelines
| Jurisdiction | Timeline | Extension |
|---|---|---|
| PIPEDA | 30 days | Additional 30 days with notice |
| Quebec Law 25 | 30 days | Additional 10 days with notice |
| GDPR (for comparison) | 30 days | Additional 60 days with notice |
Penalties for Non-Compliance
Failure to Process Deletion Requests
| Law | Maximum Penalty |
|---|---|
| PIPEDA | $100,000 per violation |
| Quebec Law 25 | $25,000,000 or 4% global revenue |
Common Violations
- Failing to respond within 30 days
- Not deleting from all systems
- Not notifying third parties
- Refusing without valid justification
- Charging fees for deletion requests
Frequently Asked Questions
Q: Can I charge a fee for processing deletion requests? Under PIPEDA, you can charge a minimal fee for access requests but not for deletion. Law 25 prohibits fees for exercising privacy rights.
Q: What if deleting data would break my system? You must find a technical solution. "It's too hard" is not a valid excuse. Anonymization may be an acceptable alternative in some cases.
Q: How do I delete data from blockchain systems? This is an evolving legal question. Consider storing personal data off-chain with only hashes on-chain, or use privacy-preserving blockchain architectures.
Q: Do I need to delete data from all backups? Best practice is to delete from active systems immediately and from backups on a reasonable schedule. Document your approach.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Related Articles:
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Children's Privacy Protection in Canada: PIPEDA Rules for Collecting Minor's Data
Children's privacy in Canada: consent for minors under PIPEDA and provincial law, age verification, ...
Canada GDPR Adequacy Decision: What It Means for EU-Canada Data Transfers in 2026
Understand Canada's GDPR adequacy status, its limitations, and what Canadian businesses need for law...