By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: Handling individual privacy rights requests is a legal obligation for any business subject to Canadian privacy law. Under PIPEDA and Quebec Law 25, individuals have the right to access their personal information held by an organization, challenge its accuracy, and in some cases request its correction, deletion, or portability, and organizations must respond within defined timelines. Most organizations handle these requests inconsistently because they have no structured process: no intake channel, no identity verification procedure, no system for locating personal information across all repositories, and no response templates. The resulting delays and errors are a direct regulatory compliance risk.
Key Takeaways
- PIPEDA requires organizations to respond to individual access requests within 30 days, with a permitted extension of up to 30 additional days in limited circumstances. Quebec Law 25 requires a response within 30 days as well, but unlike PIPEDA it gives businesses no unilateral extension: more time must be requested from the CAI before the deadline, and a missed deadline is deemed a refusal. Failure to respond on time is itself a violation, independent of whether the information exists or is provided correctly.
- Identity verification is the most commonly mishandled step. The organization must verify that the requester is the individual whose information is being requested, using a proportionate verification method that does not itself collect more personal information than necessary. Getting this wrong creates liability in both directions: over-disclosure to an unverified requester, or refusal to disclose to a verified individual.
- Personal information may be distributed across multiple systems, databases, email archives, cloud storage, vendor records, and paper files. A complete response requires searching all relevant repositories, not just the primary customer database. Organizations without a personal information inventory struggle to conduct complete searches within the required timeline.
- Portability is a new right under Quebec Law 25 that has no equivalent in PIPEDA. Individuals subject to Quebec law can request that their personal information be communicated to them or to another organization in a structured, commonly used technological format. This requires technical capability that many organizations do not have in place.
- Every individual rights request must be documented, regardless of whether personal information was found and provided. The documentation is the evidence of compliance that regulators and courts review when a complaint is filed.
What Rights Individuals Have Under Canadian Privacy Law
PIPEDA’s individual access principle gives individuals the right to request access to personal information that an organization holds about them, to know how that information is being used and to whom it has been disclosed, and to challenge the accuracy and completeness of the information and have it corrected where appropriate. The right of access is subject to exceptions for information about other individuals, legally privileged information, information that would reveal confidential commercial information, and information collected in the context of an investigation of a breach of an agreement or a law. These rights sit within the broader framework of PIPEDA and Quebec Law 25 business compliance.
Quebec Law 25 provides the same access and correction rights and adds new rights that go beyond PIPEDA. The right to de-indexation allows individuals to request the cessation of dissemination of their personal information and the re-indexation of any hyperlinks associated with their name where dissemination causes serious injury, where the information is used for purposes for which consent was not given, or where the information was collected from a minor. The right to portability allows individuals to receive their personal information in a structured, commonly used technological format and to have it communicated to another organization. Quebec Law 25 also strengthens the right to withdraw consent, requiring that withdrawal be as simple as giving consent and that withdrawal be respected within a reasonable time.
What a Compliant Individual Privacy Rights Process Looks Like
Intake channel
Individuals need a clear, accessible way to submit a rights request. The intake channel should be described in the organization’s privacy policy and privacy notice, and it should be easy to find. A dedicated email address, a web form, or a written request process are all acceptable intake mechanisms. The channel should capture the information needed to process the request: the requester’s name, contact information, the nature of the request (access, correction, deletion, portability), and any specifics about the personal information or processing activity at issue. The intake record is the start of the documentation trail that the organization maintains for the request.
Identity verification
Before disclosing personal information, the organization must verify that the requester is the individual whose information is at issue or is otherwise authorized to make the request on that individual’s behalf. The verification method must be proportionate: for a request involving low-sensitivity personal information, asking the individual to confirm information already on file such as their account email and a security question may be sufficient. For requests involving sensitive personal information including health, financial, or biometric data, a more robust verification method may be warranted. The verification method should not itself require the individual to provide more personal information than is necessary for the purpose of verification.
Search and retrieval
A complete response requires locating all personal information about the requester held across all relevant repositories. This is the step where organizations without a personal information inventory consistently fail. The search must cover primary databases and customer systems, email archives where communications with or about the individual may be stored, document management systems and file shares, cloud storage and collaboration platforms, vendor records where the vendor processes personal information on the organization’s behalf, and in some cases paper files. Because third parties are in scope, the search protocol ties directly into vendor and supplier risk management. Organizations whose personal information is distributed across many systems require a documented search protocol that defines which repositories are searched, in what order, and by whom, so the process is consistent and complete across all requests.
Review and response
Before responding, the organization must review the retrieved information to identify whether any exceptions apply: information about other individuals that must be redacted, legally privileged material, commercially sensitive information, or information collected in an investigative context. The response must explain what information was found and provided, what was withheld and on what grounds, and how the individual can challenge the response if they believe it is incomplete or incorrect. The response must be provided in a format that is understandable to the individual. A response that produces a database export in a format the individual cannot read without technical assistance is not an adequate response.
Timeline management
PIPEDA requires a response within 30 days of receipt of the request. An extension of up to 30 additional days is permitted where meeting the original deadline would unreasonably interfere with the organization’s operations or where additional time is required to consult with third parties, and the individual must be notified of any extension within the original 30-day period and given the reason. Quebec Law 25 also requires a response within 30 days, but it does not give businesses the same unilateral extension: under the private sector Act, more time must be requested from the CAI before the deadline expires, and a failure to respond within 30 days is legally deemed a refusal. Timeline management therefore requires a tracking system: a log of all requests received, the date of receipt, the date of response or extension notice, and the outcome. Without tracking, organizations routinely miss the deadline without realizing it.
Documentation and recordkeeping
Every individual rights request must be documented from receipt through closure, regardless of outcome. The documentation includes the original request, the identity verification record, the search protocol and its results, the review and redaction decisions and their basis, the response sent, the date of response, and any follow-up from the requester. This documentation is the evidence of compliance that the regulator reviews when a complaint is filed alleging that the organization failed to respond adequately to a request. Organizations that cannot produce this documentation in response to a complaint investigation are at a significant disadvantage.
Armour Cybersecurity builds the complete individual rights management process as part of the privacy risk management engagement, including intake channels, identity verification procedures, search protocols tied to the personal information inventory, response templates, timeline tracking, and documentation standards. It is one of the components that separates a privacy policy from an operational program, the distinction covered in why a privacy policy is not a privacy risk management program.
Common Failure Modes in Individual Rights Handling
The most common failure in individual rights handling is a response that is late, incomplete, or both. Late responses occur because no one owns the process, because the request arrived through an informal channel and was not recognized as a formal rights request, or because the timeline was not tracked. Incomplete responses occur because the search did not cover all relevant repositories, because redaction was not applied consistently, or because the response did not explain what was withheld and why.
A second common failure is inadequate identity verification: either not verifying at all and disclosing to an unverified requester, or applying verification requirements so burdensome that they effectively deny access to legitimate requesters. A third is failure to handle correction requests: when an individual challenges the accuracy of their personal information, the organization must amend the information or explain why amendment is not warranted, and must notify any third parties to whom the incorrect information was disclosed. Many organizations acknowledge correction requests but do not follow through on the downstream notification requirement. Managing these consistently is part of a broader governance, risk and compliance discipline.
Frequently Asked Questions
Can we charge a fee for responding to a PIPEDA access request?
PIPEDA does not prohibit charging a minimal fee for access requests, but organizations must inform the individual of the fee before processing the request and must not charge more than is reasonable given the costs involved. In practice, most organizations do not charge fees because the administrative complexity of explaining and collecting a fee exceeds the value of the fee for most requests. Under Quebec Law 25, access requests must be processed free of charge, with a reasonable fee permitted only where a request is clearly abusive or repetitive. If a fee would be charged for some but not all requests, the organization’s privacy policy should describe the circumstances under which a fee applies.
What do we do when a request is complex and cannot be completed in 30 days?
Under PIPEDA, notify the individual within the original 30-day period that additional time is required, provide the reason for the extension, and indicate when the response will be provided; the extension is a further 30 days. Under Quebec Law 25 the rule is stricter for businesses: there is no unilateral extension, so if you cannot meet the 30-day deadline you must apply to the CAI for more time before it expires. If the complexity is driven by the volume of information involved, consider prioritizing the retrieval of the most recently collected information and responding in stages while the broader search continues. Document the extension and its basis in the request record. If the organization routinely struggles to meet the timeline, the underlying cause is typically a personal information inventory that is insufficient to support timely searches, which is a program gap that requires remediation.
Do we have to respond to requests from former customers or employees?
Yes. PIPEDA and Quebec Law 25 apply to personal information held about any identifiable individual, not only current customers or employees. Former employees whose personnel records are retained, former customers whose transaction history is in the database, and former partners or contractors whose contact information is maintained all have the same access rights as current relationships. The organization must respond to their requests within the same timelines and to the same standard. The only limitation is that the organization is only required to provide information it actually holds: if records have been deleted pursuant to a documented retention schedule, the organization should document the search and its result and explain to the requester that no information was found.
How do portability requests work under Quebec Law 25?
A portability request under Quebec Law 25 requires the organization to communicate the individual’s computerized personal information to them, or to another organization designated by the individual, in a structured, commonly used technological format, and it follows the same 30-day response rule as an access request. The right is subject to exceptions where communication would not be technologically feasible or where it would disclose personal information about a third party. Practically, portability requires that the organization can extract the individual’s personal information from its systems in a format such as JSON, CSV, or XML that can be read and used by another system. Organizations that do not have this technical capability need to develop it as part of their Law 25 compliance program.
What happens if an individual files a complaint about our handling of their rights request?
A complaint to the Office of the Privacy Commissioner or the Commission d’acces a l’information triggers an investigation. The regulator will request the organization’s documentation of the request handling: the intake record, the identity verification record, the search results, the response, and the timeline. The organization should respond promptly and cooperatively, providing complete documentation. Where the investigation finds that the response was late, incomplete, or incorrect, the regulator will issue findings and may make recommendations for remediation. Under Quebec Law 25, where the violation meets the threshold for a penalty, the CAI can impose administrative monetary penalties. The best response to a complaint is complete, organized documentation demonstrating that the process was followed correctly. The best prevention is having the process in place before the next complaint arrives.

The Bottom Line
Individual privacy rights requests are not an occasional inconvenience; they are a legal obligation with a clock attached and a penalty for missing it. Handling them well in business means a real process: a findable intake channel, proportionate identity verification, a search protocol tied to a personal information inventory, consistent review and redaction, tracked timelines, and complete documentation. Improvising each request is how organizations end up late, incomplete, or over-disclosing. A structured privacy risk management program puts that process in place before the next request arrives. Start with a current-state review of how requests are handled today, then build the intake, search, and tracking the law assumes you already have.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



