PIPEDA's consent principle requires that consent be meaningful: the client must understand what information is being collected, why, how it will be used, and with whom it may be shared, so that consent is genuinely informed.
In the insurance context, personal information collected at application includes medical history, lifestyle data (smoking, travel, dangerous activities), financial information, occupation, and family history. The agent must explain:
- What information will be shared with the insurer and any reinsurers
- That the insurer may access third-party sources such as the Medical Information Bureau (MIB), prescription drug databases, and motor vehicle records
- That claims information may be shared with industry databases for fraud prevention
Consent obtained at application is purpose-specific. If the agent or insurer wishes to use the client's data for a new purpose -- such as marketing a new product line, sharing data with an affiliated company, or using telematics data for renewal rating -- fresh consent is required for the new purpose.
Withdrawal of consent: A client may withdraw consent at any time subject to legal or contractual restrictions. An agent cannot prevent withdrawal or threaten consequences beyond what is legally and contractually required.
Common mistake: believing that a single consent form at application covers all future uses of the client's data. The scope of consent is tied to the specific purposes disclosed. A materially new use requires a new consent.
Recall: What three items must be explained to a client before obtaining meaningful consent for data collection? What happens when the insurer wishes to use the data for a new purpose after the original collection?