Canadian Privacy
Featured

Right to Be Forgotten in Canada: Data Deletion Rights Under PIPEDA and Law 25

Complete guide to data deletion and de-indexing rights in Canada. Learn how PIPEDA and Law 25 handle erasure requests, and what the never-enacted CPPA proposed.

Canada Compliance AI• Compliance Team
March 4, 2026
Updated September 12, 2026
12 min read
Right to Erasure
Data Deletion
PIPEDA
Law 25
De-indexing

The "right to be forgotten" is evolving rapidly in Canada. While PIPEDA doesn't explicitly include a GDPR-style right to erasure, Quebec's Law 25 has established robust data deletion rights for Quebecers. (The CPPA proposed in Bill C-27 would have added federal deletion rights, but it never became law.)

Current State of Data Deletion in Canada

PIPEDA's Approach

PIPEDA provides indirect deletion rights through several principles:

Principle 5 — Limiting Use, Disclosure, and Retention: Personal information shall be retained only as long as necessary for the fulfillment of those purposes.

Principle 9 — Individual Access: Upon request, individuals shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information.

OPC Interpretation: The OPC has consistently held that once the purpose for collection has been fulfilled and there's no legal retention requirement, individuals can request deletion.

Quebec Law 25: Explicit Deletion and De-indexing Rights

Law 25 creates Canada's first explicit "right to be forgotten" with two components:

1. Right to Deletion (Article 28.1)

  • Right to have personal information deleted when:
    • Collection was unlawful
    • Purpose has been fulfilled
    • Consent has been withdrawn
    • Retention period has expired

2. Right to De-indexing (Article 28.1)

  • Right to have personal information de-indexed from search engines when:
    • Information causes serious harm
    • Dissemination violates law or court order
    • Information is no longer relevant to the original purpose

CPPA (Bill C-27, Never Enacted): Proposed Deletion Rights

Bill C-27 died on the Order Paper in January 2025, so the CPPA never became law. Its first-reading text would have required an organization, on an individual's written request, to dispose of their personal information as soon as feasible in certain circumstances, including where the individual had withdrawn consent (CPPA s. 55, bill text).


How to Handle Deletion Requests

Step 1: Verify the Requester's Identity

Before processing any deletion request:

  • Confirm the individual's identity
  • Don't require excessive identification
  • Use existing authentication methods where possible
  • Document the verification process

Step 2: Assess the Request

Determine whether you must comply:

You MUST delete when:

  • Consent has been withdrawn and no other legal basis exists
  • The purpose for collection has been fulfilled
  • Data was collected unlawfully
  • Retention period has expired
  • A court or regulatory order requires deletion

You MAY refuse when:

  • Legal retention obligations exist (tax, financial regulations)
  • Data is needed for ongoing legal proceedings
  • Public interest justification exists
  • Journalistic, artistic, or literary purposes
  • Archival purposes in the public interest

Step 3: Process the Deletion

Internal Systems:

  • Delete from primary databases
  • Remove from backups (where feasible)
  • Clear from cache systems
  • Remove from analytics and reporting
  • Delete from employee systems

Third Parties:

  • Notify all third parties who received the data
  • Request confirmation of deletion
  • Document the notification and responses

Step 4: Confirm Completion

  • Notify the requester within 30 days (PIPEDA) or Law 25 timelines
  • Provide confirmation of what was deleted
  • Explain any data that could not be deleted (and why)
  • Keep a record of the request and actions taken (without keeping the deleted data)

De-indexing Requests Under Law 25

How De-indexing Works

De-indexing is distinct from deletion—it removes information from search engine results without necessarily deleting the source:

  1. Individual submits request to the organization
  2. Organization assesses whether criteria are met
  3. If valid, organization contacts search engines
  4. Search engines remove the URLs from results
  5. Source pages may still exist but won't appear in searches

Criteria for De-indexing

Law 25 requires de-indexing when information:

  • Causes serious injury to the individual
  • Violates the law or a court order
  • Is no longer necessary for the original purpose
  • Does not serve the public interest

Balancing Test

Organizations must balance:

  • Individual's privacy rights
  • Public interest in the information
  • Freedom of expression
  • Historical/archival value
  • Journalistic purposes

Technical Implementation

Building a Deletion Workflow

1. Request Intake

  • Web form for deletion requests
  • Email address for privacy requests
  • Telephone option
  • Track all requests in a central system

2. Data Discovery

  • Automated search across all systems
  • Check all databases, backups, archives
  • Third-party data sharing records
  • Employee who processed the data

3. Deletion Execution

  • Automated deletion scripts where possible
  • Manual deletion for unstructured data
  • Backup retention policies
  • Cache invalidation

4. Verification

  • Confirm deletion across all systems
  • Third-party confirmation
  • Audit trail
  • Quality assurance check

Handling Backups

One of the most challenging aspects of data deletion:

Option 1: Delete from backups immediately

  • Most compliant approach
  • Technically complex and expensive
  • May affect backup integrity

Option 2: Encrypt and schedule deletion

  • Mark data for deletion in next backup cycle
  • Encrypt in interim
  • Ensure data isn't restored during normal recovery

Option 3: Documentation approach

  • Document the deletion request
  • Delete from active systems immediately
  • Delete from backups per retention schedule
  • Ensure data isn't restored from backups

OPC Guidance: The OPC has accepted that backup deletion may follow a reasonable schedule, but active systems must be cleaned immediately.


Industry-Specific Considerations

Financial Services

  • Tax records: 7-year retention requirement
  • Anti-money laundering: 5-year retention after account closure
  • Investment records: 7+ year retention
  • Partial deletion permitted: Delete what you can, retain what you must

Healthcare

  • Patient records: 10+ years in most provinces
  • Medical imaging: Varies by province
  • Mental health records: Enhanced protections
  • Cannot delete most health records during retention period

E-Commerce

  • Transaction records: 7 years (tax purposes)
  • Customer profiles: Delete upon request
  • Marketing data: Delete immediately upon request
  • Reviews and ratings: Complex—may be anonymized instead

HR/Employment

  • Personnel files: 2-7 years post-employment
  • Payroll records: 7 years
  • Applications (rejected): 6 months recommended
  • Reference checks: Delete once hiring decision made

Response Timelines

JurisdictionTimelineExtension
PIPEDA30 daysAdditional 30 days with notice
Quebec Law 2530 daysAdditional 10 days with notice
GDPR (for comparison)30 daysAdditional 60 days with notice

Penalties for Non-Compliance

Failure to Process Deletion Requests

LawMaximum Penalty
PIPEDA$100,000 per violation
Quebec Law 25$25,000,000 or 4% global revenue

Common Violations

  • Failing to respond within 30 days
  • Not deleting from all systems
  • Not notifying third parties
  • Refusing without valid justification
  • Charging fees for deletion requests

Frequently Asked Questions

Q: Can I charge a fee for processing deletion requests? Under PIPEDA, you can charge a minimal fee for access requests but not for deletion. Law 25 prohibits fees for exercising privacy rights.

Q: What if deleting data would break my system? You must find a technical solution. "It's too hard" is not a valid excuse. Anonymization may be an acceptable alternative in some cases.

Q: How do I delete data from blockchain systems? This is an evolving legal question. Consider storing personal data off-chain with only hashes on-chain, or use privacy-preserving blockchain architectures.

Q: Do I need to delete data from all backups? Best practice is to delete from active systems immediately and from backups on a reasonable schedule. Document your approach.


Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Related Articles:

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.