Back to Blog
Privacy Rights July 9, 2026 7 min read

Handling a DSAR Data Access Request in Canada Without Panic

Most access requests don't go wrong through malice. They go wrong because an ordinary-looking email turns out to be a 30-day legal clock nobody noticed. Here's the process that keeps a DSAR from becoming a regulator complaint.

By Valdra Team

Handling a DSAR Data Access Request in Canada Without Panic

A logistics company in Mississauga got an email last spring that started with "I would like a copy of all personal information you hold about me." No subject line clue, no legal letterhead, just a former contractor who'd had a falling-out over an unpaid invoice. The office manager forwarded it to three people, nobody claimed it, and it sat for five weeks. By the time someone realized a clock had been running, they were already past the deadline and the requester had filed a complaint with the Office of the Privacy Commissioner of Canada.

That is how most access requests go sideways in this country. Not through malice or some grand failure of competence, but through a quiet refusal to recognize that an ordinary-looking email is a legal obligation with a fixed timer attached.

What actually counts as a DSAR data access request in Canada

The term "DSAR" (data subject access request) is borrowed from Europe's GDPR, and Canadians use it loosely. Under our law the right has two halves: the right to access the personal information an organization holds about you, and the right to correction when that information is wrong or incomplete. PIPEDA spells these out in Principle 9 (Individual Access) of Schedule 1. Quebec's Law 25, which overhauled the province's private-sector privacy act, gives residents the same access and rectification rights plus a few sharper ones, including a data portability right that came into force in September 2024.

Here is the part people miss: a valid request does not need to use the word "access," cite a statute, or arrive on a form. If a person asks what you know about them and asks for it back, you have received a request. The email above was a DSAR. So is a customer-service chat message that says "send me everything you've got on my account." Treating only the formal-looking ones as real is the single most common way organizations blow the deadline.

You can ask the person to clarify scope, and you should when the request is genuinely vague. What you cannot do is use a clarification question as a stalling tactic. The OPC has been explicit that the clock does not reset every time you reply with a question.

The timelines, and why they are not the same

This trips up businesses that operate across provinces, so be precise about it.

Under PIPEDA, you must respond to an access request within 30 days of receiving it. You can extend by a further 30 days in three defined situations: when meeting the original deadline would unreasonably interfere with your operations, when you need time for necessary consultations, or when converting the data into an accessible alternative format takes significant time. If you take the extension, you have to notify the individual in writing within the original 30 days, give them the new date and the reason, and tell them they can complain to the OPC about the extension itself. Sixty days is the practical ceiling.

Under Quebec's Law 25, the response deadline is also 30 days (section 32 of the private-sector act), and the Commission d'accès à l'information (CAI) enforces it. Quebec does not hand you the same self-granted second window that PIPEDA does. An extension under Law 25 requires you to apply to the CAI before the original deadline expires, which is a higher bar than simply writing to the requester. Plan around the tighter posture, because the CAI has both the appetite and the penalty powers the OPC currently lacks: administrative monetary penalties up to $10 million or 2% of worldwide turnover, plus a separate penal track reaching $25 million or 4% for the most serious violations.

For health information the goalposts move again. Ontario's PHIPA, enforced by the province's Information and Privacy Commissioner (IPC), gives health information custodians 30 days to respond, extendable by another 30 in specific circumstances. Miss it without notice and you are deemed to have refused the request. Different statute, different regulator, similar rhythm, but you cannot assume the PIPEDA rules map cleanly onto health records.

A request that costs you nothing to fulfill should usually cost the requester nothing either. PIPEDA permits only minimal cost recovery and requires you to give an advance estimate. In practice, charging individuals to see their own data is a reputational landmine, and most organizations have stopped doing it.

A process that survives contact with a real request

Panic is what happens in the absence of a process. Build it once and the next request becomes paperwork instead of a fire drill.

Log it the moment it lands. Date-stamp every request in one place the day it arrives, not the day someone gets around to it. The receipt date starts your 30 days, and you want a defensible record of it. A shared inbox with a triage owner beats hoping the right person notices.

Verify identity proportionately. You have to confirm the requester is who they claim to be, but the verification must match the sensitivity of the data. Demanding a notarized passport copy to release someone's newsletter preferences is its own privacy problem, because you have just collected more sensitive ID than the underlying records warranted. Match the friction to the risk.

Find everything, including the awkward places. This is where the work actually lives. Personal information hides in your CRM, your email archives, support-ticket systems, call recordings, marketing platforms, backups, and the spreadsheet someone keeps on their desktop. A real access response reaches across all of it. If you have a current data map, this step takes an afternoon. If you don't, this is the request that forces you to build one.

Know what you can and must hold back. Access is not absolute. You must refuse to disclose personal information about other identifiable individuals where it cannot be severed, you may withhold solicitor-client privileged material, and there are carve-outs for information that would reveal confidential commercial data or compromise an investigation. When part of a record is exempt, redact that part and release the rest. Blanket refusal because one paragraph is sensitive does not hold up.

Respond in a usable form, and explain refusals. Give the information in a format the person can actually read. Where you deny any part of the request, you have to tell them why, point to the provision you are relying on, and inform them of their right to complain to the relevant regulator.

Correction requests need their own muscle memory

Access gets the attention; correction is where organizations quietly fail. When someone tells you a record is wrong, you either amend it or, if you disagree, you note the disagreement on the file. Under PIPEDA you also have to flag the correction to any third party that received the bad data, where it matters. Quebec's rectification right works the same way, and the CAI takes it seriously.

The practical trap is the "we disagree" case. You are not required to accept every correction, but you are required to record that the individual contested the information. Skipping that annotation is a common, avoidable violation.

What a single missed request really costs

The Mississauga company settled its OPC complaint by overhauling its intake process, which is the predictable ending. The deeper cost was time: weeks of senior-staff scramble, a lawyer's hours, and a finding on file. None of it was about the data itself, which turned out to be a handful of unremarkable invoices and emails. It was about not having a system.

That asymmetry is the whole argument. A DSAR data access request in Canada is, on its own, mundane. Mishandled at scale, across PIPEDA, Law 25, and PHIPA deadlines you are tracking by hand, it becomes the thing that pulls you into a regulator's orbit. The fix is boring and effective: log, verify, search, sever, respond, on a calendar you trust.

Small and mid-sized teams rarely have a privacy officer sitting around waiting for these. That is exactly the case where software earns its keep, starting the clock automatically, routing the search, tracking the deadline against the right province, and producing a defensible record of what you did and when. If you'd rather handle the next access request as a workflow than as an emergency, see how Valdra manages access and correction requests end to end.

DSAR data access request CanadaPIPEDA access requestLaw 25 access requestdata subject access request CanadaPIPEDA 30 day deadlineprivacy correction request Canada

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

DSAR Data Access Request Canada: The Process | Valdra