Step 7 of 978%
7

Access and Rectification Requests: Responding Under Law 25

Allow your clients to request access to or rectification of their personal information.

Estimated time: 30 minutes
Updated July 30, 2026

The essentials

Everyone has the right to know what personal information your business holds about them, to access it, and to have it rectified if it is inaccurate, incomplete or ambiguous.

Your business has 30 days to respond to a request. With no response by the deadline, the request is deemed refused and the person can turn to the CAI (application for examination of a disagreement).

A refusal must be justified in writing: the legal provision it relies on, the available remedies and their deadlines.

What the law says

Law 25 gives everyone the right:

  • To access the personal information an organization holds about them
  • To request its rectification if it is incomplete, inaccurate or ambiguous

Businesses must provide a clear, simple way to receive and process these requests. The form must make it possible to:

  • Identify the requester
  • Specify the type of request (access or rectification)
  • Describe the information concerned
  • Indicate how the response will be delivered
  • Provide the requester's signature and the date

For a small business

A simple, clear, standardized form helps to:

Good to know

You have 30 days to respond to an access or rectification request. An additional 10-day extension may be granted in some cases, but you must inform the requester before the initial deadline expires.

Concrete examples

Example 1: A private school posts a PDF form online allowing a parent to request the rectification of the address in their child's file.

The parent fills out the form and emails it to the privacy officer, who confirms receipt, makes the change and responds within 15 days.

Example 2: An online retailer adds a "My personal data" link in its website footer, leading to a web form.

Customers can use it to request a copy of their data or its deletion. Each request automatically generates an email to the privacy officer with a tracking number.

Handling an access request in practice

The privacy officer, the person in charge of the protection of personal information, receives and handles requests. The typical process: verify the requester's identity, locate the information (your inventory makes this step fast), and prepare the written response within the 30-day deadline.

Watch out for third-party information: if a document contains information about other people, it must be removed or redacted before disclosure.

Verifying identity without creating a new incident

The classic trap of an access request: responding to a fraudster posing as your client. Disclosing a file to the wrong person would itself constitute a confidentiality incident.

The right reflexes: reply through the channel already on file (the email address on the client account, not the one on the request if they differ), ask for proof of identity proportionate to the sensitivity of the data, and never include more information than was requested.

The path of an access request, with deadlines

Point in timeWhat must happen
Receipt of the requestForwarding to the privacy officer and verification of the requester's identity
Days 1 to 30Locating the information, removing third-party data, written response
Day 30 with no responseThe request is deemed refused; the person can turn to the CAI
In the event of a refusalWritten reasons: the legal provision relied on, available remedies, deadlines
After a refusalThe person has 30 days to ask the CAI to examine the disagreement

Mistakes to avoid

  • Not offering a form and asking people to "just send an email"
  • Not specifying the supporting documents required
  • Not indicating the response time frames
  • Forgetting to record the request and the response in an internal register

Step-by-step instructions

1
Create a clear, easy-to-complete form (PDF, Word or online)
2
Include all the necessary information (identity, nature of the request, information concerned, signature)
3
Determine who the form must be sent to and how
4
Set up an internal process to handle the request within the deadlines
5
Keep a copy of each request and response in an internal register

Checklist: Step 7 complete?

  • I have an official form for access and rectification requests
  • The form is accessible to my clients
  • I know who handles these requests in my business
  • I know the legal response deadline (30 days)
  • I have a register to document requests and responses
  • The required supporting documents are specified

Templates included in the Law 25 Kit

  • Personal Information Access or Rectification Request Form template
Get these templates

Frequently asked questions

Who can make an access request?

The person concerned, or their authorized representative. You must verify the requester's identity before disclosing anything: responding to the wrong person would itself be a confidentiality incident.

What is the deadline to respond?

30 days following receipt of the request. Failure to respond amounts to a refusal, which opens the person's recourse before the CAI.

Can a request be refused?

Yes, in the cases provided for by law (for example, when disclosure would reveal information about a third party). The refusal must be in writing and justified: the legal provision relied on, the available remedies, and the deadlines to exercise them.

What if we hold nothing about the person?

Say so in writing within the deadline. A clear, documented response, even a negative one, demonstrates your compliance and avoids an unnecessary complaint.