Canada's PIPEDA Explained: What You Can Ask Companies to Delete
TL;DR: PIPEDA (Canada's federal private-sector privacy law) gives you the right to know what personal data a company holds, correct it, and in many cases withdraw consent for its continued use. Here's how it works in practice.
👉 See if your data's already leaked — free 30-second check →
PIPEDA — the Personal Information Protection and Electronic Documents Act — governs how private-sector organizations across most of Canada handle personal information. It's built around consent: companies generally need your permission to collect, use, or share your data, and you can withdraw that consent later.
What you can actually request
- Access to your data. You can ask any organization covered by PIPEDA what personal information they hold about you and how it's being used.
- Correction of inaccurate data. If information is wrong, you can request a correction, and the organization must annotate the record if they disagree with your correction rather than simply ignoring it.
- Withdrawal of consent. You can withdraw consent for a company to keep using your data for a given purpose, subject to legal or contractual limitations.
Unlike GDPR, PIPEDA doesn't have an explicit standalone "right to erasure" written into the law — deletion typically happens as a consequence of withdrawing consent when there's no other legal basis for the company to keep the data, rather than as a distinct request type.
How to make a request in practice
Organizations are required to have a designated privacy officer or contact point, usually listed in their privacy policy. A written request describing what you're asking for — access, correction, or consent withdrawal — is generally the starting point, and organizations must respond within 30 days.
If a company doesn't cooperate
The Office of the Privacy Commissioner of Canada handles complaints against organizations that don't comply with PIPEDA obligations, and filing a complaint is free.
Every country's framework works a little differently — for the EU version, see what GDPR lets you request, and for how India's own framework compares, see what rights the DPDP Act gives you. Regardless of jurisdiction, it helps to know what's already exposed before filing requests — a Scan My Shadow report checks your phone number and email across 1,500+ sources.
Frequently Asked Questions
Does PIPEDA cover government agencies too?
No — PIPEDA covers private-sector organizations; federal government institutions are covered separately under the Privacy Act, and some provinces have their own private-sector laws that may apply instead of PIPEDA.
Can I request that a company delete my data outright under PIPEDA?
Not as a standalone right the way GDPR provides — deletion generally follows from withdrawing consent when the company has no other valid reason to retain the data.
How long does a company have to respond to a PIPEDA request?
Generally 30 days, with the possibility of an extension in certain circumstances if they notify you.
Is filing a complaint with the Privacy Commissioner free?
Yes, there's no cost to file a complaint if an organization doesn't comply with your request.
Does PIPEDA apply to companies outside Canada?
It can apply if the organization has a real and substantial connection to Canada, such as actively doing business with Canadian residents, similar in spirit to how GDPR reaches beyond EU borders.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated