Canada’s Bill C-36 — which will substantially reform its private sector data protection regime — proposes a right for individuals to request the disposal of their data by organizations that have collected it. This post will consider the rationale behind the right, and the competing interests it runs up against. It also looks at the scope and limitations of the proposed right. The exceptions to this right are different in C-36 over its predecessor Bill C-27 in some significant ways and these changes will also be assessed.
The right of an individual to request that an organization dispose of the personal data that it holds about them is linked to basic data protection principles. It strengthens individual control over their personal data. It also reinforces the principle of limiting the use, disclosure and retention of data. It helps with the safeguarding of personal data because the less personal information that is hanging around, the less that can be compromised in a data breach.
To this end, Bill C-36 proposes a right to request disposal of personal information in the following circumstances:
54 (1) If an organization receives a written request from an individual to dispose of their personal information that is under the organization’s control, the organization must, as soon as feasible, dispose of the information, if
(a) the information was collected, used or disclosed in contravention of this Act;
(b) the individual has withdrawn their consent, in whole or in part, to the collection, use or disclosure of the information; or
(c) the information is no longer necessary for the continued provision of a product or service requested by the individual.
Organizations must make information about how to make such a request readily available (s. 62(2)(f)). In practical terms, the right of deletion can be complex for organizations. Some organizations may be required under federal or provincial laws to retain certain information for specified purposes. For example, financial institutions are heavily regulated and have a range of legal requirements to record and retain data for various purposes. It is also generally good practice for organizations to retain personal data for periods long enough to address potential customer complaints or that may surface in legal claims. In some cases, the data collected and retained by the organization will be directly linked to the services provided. For example, if an automated vacuum cleaner maps the purchaser’s home to more effectively clean around obstacles, then deleting the data on the request of the customer while the customer continues to use the product will impair its functioning. The right of disposal can also be tricky when an organization has already shared the personal information with another organization.
Bill C-36 attempts to balance these concerns with the right to disposal. For example, s. 54(2)(b) provides that a request for disposal can be refused if other legal or contractual requirements prevent the organization from doing so. Section 54(2)(c) creates an exception where the organization needs to retain the information “for the establishment of a legal defence or in the exercise of other legal remedies by the organization.” Disposal can also be refused if “the information is not in relation to a child and the disposal of the information would have an undue adverse effect on the accuracy or integrity of information that is necessary to the ongoing provision of a product or service to the individual in question” (s. 54(2)(d)). The non-application of this exception to the personal information of children is meant to enhance children’s privacy, but the wording of the exception, means that the accuracy and integrity of a product or service that continues to be provided can be adversely affected in the case of a child. A parent acting in their child’s best interest is unlikely to think “I should have necessary personal information deleted so that my child has a poor user experience with this site – that will teach them!”. They are more likely to think: “This is not an appropriate site for my child. I want the account closed and the personal information to be deleted.”
Another exception in s. 54(2)(a) allows an organization to refuse a disposal request where “the disposal of the information would result in the disposal of personal information about another individual, and the information cannot be severed without imposing an undue burden on the organization”. This will be an interesting one to watch. For example, assume that you are troubled by online photographs posted by third parties of you having way too much fun at parties – just when you are applying for jobs. The photos were posted without your consent, and you ask the platform company to remove your personal information. Since you are featured in the photos with other people who have not requested disposal, the organization could refuse to take down the photograph. The issue would then become whether they are required to blur your identifying features in the photograph or whether such severance would impose “an undue burden”.
The list of exceptions also gives organizations the right to refuse a request if it is “vexatious or made in bad faith” (s. 54(2)(e)). Certainly, organizations do not want to be targeted by campaigns designed to overrun their systems with the filing of massive volumes of requests, and they should be protected against this. They may also not want to have to respond to large numbers of requests from an individual who, for example, has made it their mission to track down every non-consented-to photo of themselves found on social media platforms and request at least a severance of their personal information. The challenge will be in determining how to understand “frivolous and vexatious” in a context in which individuals have a right to request that organizations dispose of their personal information that (vexatiously) has been collected without their consent – or otherwise in contravention of the law.
Organizations that have transferred personal information to a service provider (or example, for processing on behalf of the organization) and that must dispose of that information in response to a request for disposal must notify the service provider and must ensure that the information is disposed of. This obligation does not apply where information has been sold to third parties.
A new exception in Bill C-36 replaces an exception from Bill C-27 that had raised some concerns. Section 55(2)(f) of Bill C-27 would have allowed organizations to refuse to delete personal information (so long as it was not in relation to a minor) if it was “scheduled to be disposed of in accordance with the organization’s information retention policy, and the organization informs the individual of the remaining period of time for which the information will be retained.” In other words, if the organization had a policy that it would delete all personal information of a certain category three years after its date of collection, anyone who applied earlier than the end of this three-year period could have their request refused on the basis that the information would be deleted according to the existing schedule. One of the challenges with this exception was that it was bound to create a frustrating loop for both individuals and organizations. The individual, believing they had a right to deletion would make a request, only to have their request denied in exchange for a promise of future deletion. The organization would find itself in the position of irritating customers by denying their requests, and both individuals and organizations would be writing emails to each other. The goal of the exception was no doubt to give organizations an incentive to put in place schedules for disposal of personal information, but the quid pro quo for doing so might be getting accused on social media of giving customers the run around.
Bill C-36 has removed this exception. Instead, it creates two new bases for refusal of a request to dispose of personal information. The first is where:
54(2)(f) the disposal of the information would have an undue adverse effect on the organization that outweighs any potential adverse effect on the individual resulting from the retention of the information.
This is troublingly squishy. First, the adverse effect on the organization would have to be “undue”, and it is far from clear what that might mean. Further, the balancing test requires speculation about potential adverse effects on the individual resulting from the retention of the information. For example, an organization with cutting edge data security practices holding only non-sensitive personal data might consider that retention would have minimal adverse effects for the individual. But it is not clear how an individual will be satisfied with this if what they want is to exercise their right to have their personal information deleted. If deletion is meant to enhance the right of control, then removing that control from the individual seems inherently to be an adverse effect. Keep in mind that the circumstances in which an individual may request deletion include where the information has been collected, used or disclosed in contravention of the legislation, where the individual has withdrawn their consent, or where the information is no longer necessary for the provision of the product or service requested by the individual. Perhaps recognizing the problematic nature of this exception, Bill C-36 provides that where an organization asserts this basis for rejecting a request for deletion, they must “inform the Commission in writing of the refusal, setting out the reasons” (s. 54(4)(b)). However, there is no further direction regarding what the Commission must do with this correspondence. They could file it under “whatever”.
The final exception for organizations – also new – is found in section 54(3) of Bill C-36. It provides that: “An organization is not required to dispose of de-identified personal information”. At first glance, this may not seem so controversial. Bill C-27 had specifically provided that the anonymization of personal information was considered disposal of that information (see definition of “dispose” in s. 2(1)). However, Bill C-27 used an absolute definition of anonymization – setting a very high threshold. While Bill C-36 also provides that disposal of personal information includes anonymization (definition of “dispose” in s. 2(1)), its threshold for anonymization is lower than in C-27). Bill C-36 then creates a further exception: the right of disposal is inoperative where information has simply been de-identified.
De-identification under Bill C-36 “means to modify personal information so that an individual cannot be directly identified from it, although a risk of the individual being identified remains.” (Definition of “d-identify” in s. 2(1)). This could mean something like removing direct identifiers (e.g. a person’s name), even though the person might still be indirectly identifiable from the remaining data. It could also mean pseudonymization – substituting a person’s direct identifiers with a code – but where the organization retains the capability to re-link the code to the direct identifier. De-identified data is not excluded from the scope of the Act because it is still considered to be personal data. Thus, under Bill C-36, an individual loses their right to request deletion of de-identified personal data even though they might still be identifiable from that data. No other conditions apply – for example, it is not necessary for the organization to establish an undue burden or a legal requirement to retain the information. Further, this exception is not tied to any specific exercise of the right to deletion. Although an individual has the right to request deletion of information collected, used, or disclosed in contravention of the Act, if this information had been de-identified, it would appear that the right to deletion is inoperative. This seems wrong.
Bill C-36 is meant to make it easier for individuals to request the removal of non-consensual intimate images and deepfakes from sites that host this content. Certainly, s. 54(1)(a) makes it clear that an organization that receives a written request from an individual for disposal of personal information must “as soon as feasible, dispose of the information” in circumstances that include where “the information was collected, used or disclosed in contravention of this Act”. If a third-party uploads content to a platform without the knowledge or consent of the individual featured in the content, this will amount to a collection by the platform of personal information without consent. Takedown (disposal) would be required. If the information is not taken down, a complaint can be filed with the new Commission, and the ensuing investigation could lead to an order. Importantly, breach of s. 54(1) can also lead to the imposition of a penalty on the organization (s. 113(1)(j)), and the penalty can be substantial. All of this is an improvement over the status quo under the Personal Information Protection and Electronic Documents Act (PIPEDA). This does not mean that a solution will be quick or easy, but once it is clear to organizations that stiff consequences will flow from non-compliance, we can hope that organizations that host third-party content will establish internal systems for addressing these sorts of complaints quickly and effectively. However, the broad exception to the right of deletion for de-identified personal information creates a big problem for this exception. It would seem that, according to s. 54(3), if an organization simply blurs the face of the non-consenting individual in the non-consensual intimate image, they do not have to respond to a request for deletion. This is not acceptable. The exception to the right of disposal in the case of de-identified personal information should be removed.
Finally, the Governor in Council has a regulation-making power under s. 139(1)(e) “respecting the disposal of personal information for the purposes of section 54”. It is possible that regulations could define particular terms or set parameters. Nevertheless, some of the issues outlined above must be dealt with in the legislation itself. Regulations are meant to flesh out a statutory scheme, not to correct its deficiencies.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.