Access and Rectification Requests: Responding Under Law 25
Allow your clients to request access to or rectification of their personal information.
The essentials
Everyone has the right to know what personal information your business holds about them, to access it, and to have it rectified if it is inaccurate, incomplete or ambiguous.
Your business has 30 days to respond to a request. With no response by the deadline, the request is deemed refused and the person can turn to the CAI (application for examination of a disagreement).
A refusal must be justified in writing: the legal provision it relies on, the available remedies and their deadlines.
What the law says
Law 25 gives everyone the right:
- To access the personal information an organization holds about them
- To request its rectification if it is incomplete, inaccurate or ambiguous
Businesses must provide a clear, simple way to receive and process these requests. The form must make it possible to:
- Identify the requester
- Specify the type of request (access or rectification)
- Describe the information concerned
- Indicate how the response will be delivered
- Provide the requester's signature and the date
For a small business
A simple, clear, standardized form helps to:
Good to know
You have 30 days to respond to an access or rectification request. An additional 10-day extension may be granted in some cases, but you must inform the requester before the initial deadline expires.
Concrete examples
Example 1: A private school posts a PDF form online allowing a parent to request the rectification of the address in their child's file.
The parent fills out the form and emails it to the privacy officer, who confirms receipt, makes the change and responds within 15 days.
Example 2: An online retailer adds a "My personal data" link in its website footer, leading to a web form.
Customers can use it to request a copy of their data or its deletion. Each request automatically generates an email to the privacy officer with a tracking number.
Handling an access request in practice
The privacy officer, the person in charge of the protection of personal information, receives and handles requests. The typical process: verify the requester's identity, locate the information (your inventory makes this step fast), and prepare the written response within the 30-day deadline.
Watch out for third-party information: if a document contains information about other people, it must be removed or redacted before disclosure.
Verifying identity without creating a new incident
The classic trap of an access request: responding to a fraudster posing as your client. Disclosing a file to the wrong person would itself constitute a confidentiality incident.
The right reflexes: reply through the channel already on file (the email address on the client account, not the one on the request if they differ), ask for proof of identity proportionate to the sensitivity of the data, and never include more information than was requested.
The path of an access request, with deadlines
| Point in time | What must happen |
|---|---|
| Receipt of the request | Forwarding to the privacy officer and verification of the requester's identity |
| Days 1 to 30 | Locating the information, removing third-party data, written response |
| Day 30 with no response | The request is deemed refused; the person can turn to the CAI |
| In the event of a refusal | Written reasons: the legal provision relied on, available remedies, deadlines |
| After a refusal | The person has 30 days to ask the CAI to examine the disagreement |
Mistakes to avoid
- Not offering a form and asking people to "just send an email"
- Not specifying the supporting documents required
- Not indicating the response time frames
- Forgetting to record the request and the response in an internal register
Step-by-step instructions
Checklist: Step 7 complete?
- I have an official form for access and rectification requests
- The form is accessible to my clients
- I know who handles these requests in my business
- I know the legal response deadline (30 days)
- I have a register to document requests and responses
- The required supporting documents are specified
Templates included in the Law 25 Kit
- Personal Information Access or Rectification Request Form template
Frequently asked questions
Who can make an access request?
The person concerned, or their authorized representative. You must verify the requester's identity before disclosing anything: responding to the wrong person would itself be a confidentiality incident.
What is the deadline to respond?
30 days following receipt of the request. Failure to respond amounts to a refusal, which opens the person's recourse before the CAI.
Can a request be refused?
Yes, in the cases provided for by law (for example, when disclosure would reveal information about a third party). The refusal must be in writing and justified: the legal provision relied on, the available remedies, and the deadlines to exercise them.
What if we hold nothing about the person?
Say so in writing within the deadline. A clear, documented response, even a negative one, demonstrates your compliance and avoids an unnecessary complaint.