- Under PIPEDA, an individual generally has the right to be told what personal information an organization holds about them, how it is being used, and to whom it has been disclosed, and to…
- You generally need to provide the personal information itself, along with information about how it has been and is being used, and to whom it has been disclosed.
- If a customer believes information you hold is inaccurate or incomplete, PIPEDA also gives them the right to request a correction.
Sooner or later, a customer will ask what personal information your business holds about them. Under PIPEDA, that is not just a customer-service question — it is a legal request with a specific process attached, and getting it wrong, by ignoring it, stalling indefinitely, or handing over the wrong thing, can create liability on its own.
This article walks through what a personal information access request actually requires of an Ontario business.
What an Access Request Actually Requires
Under PIPEDA, an individual generally has the right to be told what personal information an organization holds about them, how it is being used, and to whom it has been disclosed, and to receive access to that information, subject to specific exceptions. The request does not need to use any particular legal language — a customer asking "what information do you have on me" in an ordinary email can be enough to trigger the obligation, so businesses need a process for recognizing one even when it does not look formal.
What You Must Provide — and What You Can Withhold
You generally need to provide the personal information itself, along with information about how it has been and is being used, and to whom it has been disclosed. There are recognized exceptions — for example, where disclosure would reveal another individual's personal information, would reveal confidential commercial information, or falls under solicitor-client privilege — but these exceptions are narrow and should not be treated as a general excuse to withhold information a customer is otherwise entitled to.
Correction Requests: A Related but Different Obligation
If a customer believes information you hold is inaccurate or incomplete, PIPEDA also gives them the right to request a correction. You generally need to either make the correction, and where relevant tell others you have disclosed the information to about the change, or, if you disagree with the request, note the disagreement on file. This is a distinct step from an access request and should not be skipped just because you have already answered what information you hold.
A Step-by-Step Response Process
- Log the request the moment it arrives, including the date received. Your response clock starts running immediately, even if the request came in through an informal channel like a customer service inbox.
- Verify the requester's identity before releasing anything, without turning verification into an unreasonable barrier.
- Locate all personal information you hold about the individual, across every system you use, not just the obvious one.
- Apply any legitimate exception carefully, and be prepared to explain your reasoning if asked.
- Respond within the time period the legislation sets out — confirm the current statutory response window before committing to a date, since accurately tracking this deadline matters more than almost any other part of the process.
- Document what you provided, withheld, and why, in case the response is ever challenged.
Common Mistakes That Create Liability
- Treating an informal request — an email, a phone call — as not "official enough" to count.
- Missing the response deadline because the request sat unnoticed in a general inbox.
- Withholding information based on a vague sense that it is "sensitive," without a recognized legal basis.
- Failing to search every system that might hold the person's data, marketing platforms and old spreadsheets included.
Frequently asked questions
Can we charge a fee to respond to an access request?
PIPEDA allows a fee only in limited circumstances and generally requires you to tell the requester about any fee in advance. Treating a fee as a routine way to discourage requests is not the intent of the framework and invites scrutiny.
What if we genuinely cannot find any information about the person?
You should still respond and confirm that, after a genuine search, no responsive personal information was located. Silence is not an acceptable substitute for a proper answer.
Does a request from a former customer or former employee still count?
Generally, yes. The right to access and correct personal information is not limited to current customers or current employees.
What happens if we simply do not respond?
An unanswered access request can be escalated to a complaint to the federal Privacy Commissioner, which can lead to an investigation into not just the specific request but your broader privacy practices.
Do we have to respond the same way for a large company and a small one?
The underlying obligation is the same regardless of size, though how you organize the response can scale with your resources. A small business without a dedicated privacy team should still have a clear, written internal process for who receives a request, who verifies identity, and who signs off before information goes out.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.