A client has the right under PIPEDA to request access to their own personal information held by the insurer or the agent. On receipt of a valid access request, the organization must:
- Confirm whether it holds personal information about the individual
- Provide a copy or description of that information
- Explain how the information is or has been used and to whom it has been disclosed
There are limited exemptions (information subject to solicitor-client privilege, information about third parties that cannot be separated, investigative information), but these are narrow and the default is access.
If the client finds that information is inaccurate or incomplete, they may challenge accuracy and request a correction. The organization must either correct the record or note the disagreement.
Common mistake: treating an access request as an intrusion. It is a statutory right. Ignoring or delaying a valid access request without justification is itself a breach of PIPEDA.
Recall: What information must an organization provide when it receives a valid PIPEDA access request? Name one legitimate exemption to the access right.