← University
Privacy in the Workplace: PIPA, PIPEDA, and Employee Information
0 of 6

A request for personal information arrived on the desk of the human resources director at a mid-sized software development company based in the lower mainland of British Columbia. The request came from a senior developer who had worked for the organization for 7 years and who had recently been placed on a performance improvement plan following concerns raised by her team lead about productivity and collaboration. The employee's written request cited her rights under British Columbia's Personal Information Protection Act and asked for copies of all personal information the company held about her, including performance evaluations, internal communications referencing her, any monitoring data collected from company systems, and medical documentation she had submitted over the years in connection with accommodation requests.

The human resources director recognized that responding to this request would require the organization to confront how it had managed employee information since its founding 12 years earlier. The company had grown from a 5-person startup to an operation employing 87 staff across 3 offices, accumulating personnel files, digital records, and system-generated data without a consistent framework for organizing or retaining that information. Over the years, the organization had implemented various monitoring tools on company devices and networks, including software that logged application usage, tracked keystroke patterns during work hours, and captured screenshots at intervals throughout the day. The employee's request would require disclosure of what these systems had collected about her specifically, raising questions about whether the monitoring had been implemented with appropriate notice and consent.

The situation grew more complex when the human resources director discovered that 4 months earlier, a departing employee in the IT department had inadvertently exposed a folder containing personnel records for 23 current and former staff members to an external cloud storage service during a system migration. The breach had been identified and contained within 48 hours, but no formal breach response protocol had been followed, no affected individuals had been notified, and no report had been made to the Office of the Information and Privacy Commissioner. The senior developer's file was among those exposed.

The company's executive team now faced overlapping obligations under provincial privacy legislation. They needed to respond to the access request within the statutory timeframe, determine what notification and reporting duties arose from the earlier breach, and assess whether their existing policies and practices around employee information collection, monitoring, and retention could withstand regulatory scrutiny. The organization had no dedicated privacy officer and had never conducted a formal audit of its HR information practices.

Employee Access to Their Own Information: Rights and Employer Obligations

When employees work for an organization, they generate and contribute to a substantial body of personal information. From the moment a person submits a job application through to the end of their employment relationship and beyond, employers accumulate records that document virtually every aspect of that individual's professional life. These records might include performance evaluations, disciplinary notes, medical documentation, payroll information, communications with supervisors, incident reports, and countless other documents that paint a detailed picture of the employment relationship. Canadian privacy legislation recognizes that individuals have a fundamental interest in understanding what information is held about them and ensuring that information is accurate. This recognition forms the foundation of employee access rights, which create corresponding obligations for employers to respond to requests for personal information in a timely, complete, and transparent manner.

The legal framework governing employee access to personal information in Canada operates across federal and provincial jurisdictions, creating a layered system that employers must navigate carefully. At the federal level, the Personal Information Protection and Electronic Documents Act establishes the baseline requirements for organizations subject to federal private sector privacy law. As of the date of authorship, this legislation applies to federally regulated employers such as banks, telecommunications companies, interprovincial transportation firms, and broadcasting operations. It also applies to organizations engaged in commercial activity in provinces that have not enacted substantially similar provincial legislation. British Columbia and Alberta have both enacted their own Personal Information Protection Acts, which are recognized as substantially similar to the federal statute and therefore govern private sector employers operating within those provinces. Quebec's approach to privacy in the employment context is governed by its Act respecting the protection of personal information in the private sector, which has undergone significant modernization in recent years and contains distinct requirements that employers operating in that province must understand. For public sector employers and organizations in provinces without substantially similar legislation, the federal statute or applicable provincial public sector privacy laws determine the scope of employee access rights.

Regardless of which specific legislation applies, the underlying principle remains consistent across Canadian jurisdictions. Employees have the right to know what personal information an organization holds about them, how that information has been used, to whom it has been disclosed, and whether the information is accurate and complete. This right of access is not absolute, and legislation across jurisdictions recognizes certain exceptions and limitations, but the default position is one of transparency and individual control over personal information. Employers must understand that access requests from current or former employees are not adversarial acts to be resisted but rather legitimate exercises of legal rights that require professional, compliant responses.

The practical reality of responding to employee access requests presents challenges that many organizations underestimate. When an employee submits a written request asking to see all personal information the employer holds about them, the organization must mobilize resources across multiple departments and systems to locate, compile, review, and produce the relevant records. Personal information about employees rarely exists in a single, centralized location. Human resources maintains personnel files that might include hiring documents, performance reviews, benefit enrollment forms, and correspondence about employment terms. Payroll departments hold records of compensation, tax information, banking details, and deduction authorizations. Supervisors and managers might have emails, meeting notes, and informal documentation about specific employees stored in their individual accounts or files. Information technology departments may hold records of system access, email archives, and internet usage logs. In larger organizations, records might be scattered across multiple offices, legacy systems, cloud platforms, and physical storage locations. The challenge of locating all responsive records while meeting legislated timelines requires planning, coordination, and clear internal processes.

Timelines for responding to access requests are prescribed by legislation and cannot be extended unilaterally by the employer. Under the Personal Information Protection and Electronic Documents Act, organizations must respond to access requests within thirty days, though this period can be extended in certain circumstances with notice to the requesting individual. British Columbia's Personal Information Protection Act similarly requires response within thirty business days of receiving the request. Alberta's legislation also operates on a thirty-day timeline. Quebec's framework, following amendments that took effect in recent years, requires response within thirty days with limited extension provisions. These timelines begin running when the organization receives the request, which means employers must have systems in place to recognize access requests when they arrive and immediately begin the process of gathering responsive records. A request need not use any particular magic words or reference specific legislation to trigger the employer's obligations. An email from a departing employee asking to receive a copy of their personnel file constitutes an access request that starts the legislative clock.

The scope of information that must be produced in response to an access request extends well beyond what many employers instinctively consider part of the personnel file. Any information that is about the individual and that allows them to be identified falls within the definition of personal information under Canadian privacy legislation. This includes obvious categories like employment applications, resumes, offer letters, written performance evaluations, formal disciplinary records, and medical documentation related to leaves or accommodations. However, it also encompasses less obvious categories that employers sometimes overlook or resist producing. Emails exchanged between managers discussing the employee's performance contain personal information about that employee. Notes taken by a supervisor during a performance conversation are personal information. Investigation files related to complaints made by or against the employee contain personal information. Call monitoring records, GPS tracking data from work vehicles, security camera footage that captures the employee, and computer usage logs all constitute personal information that may be subject to access requests.

One area that creates particular complexity is information that contains personal information about multiple individuals. An investigation report into a workplace harassment complaint might contain detailed personal information about both the complainant and the respondent, as well as about witnesses who participated. Emails discussing a workplace conflict might reference several employees. Privacy legislation generally does not require organizations to produce information that would reveal personal information about other identifiable individuals, but it does require production of the requesting employee's own personal information. This often necessitates careful redaction to sever third-party personal information while preserving and producing the information about the requester. The task of redaction requires skill, consistency, and documentation of the principles applied in determining what to withhold.

Certain categories of information may be legitimately withheld from an employee access request under exceptions recognized in privacy legislation. Solicitor-client privileged communications are protected and need not be disclosed. Information compiled in reasonable anticipation of or for use in litigation may be withheld. Information that would reveal confidential commercial information of the organization may be excepted in certain circumstances. Certain evaluative and opinion information gathered for specific purposes such as determining eligibility for awards or promotions may be subject to limited exceptions depending on the applicable legislation. The existence of these exceptions does not mean employers should approach access requests looking for reasons to withhold information. The appropriate stance is one of maximum disclosure consistent with legal obligations, with exceptions applied only where clearly warranted and documented.

When an employer receives an access request, the organization must take reasonable steps to verify the identity of the requester before producing personal information. This verification serves the important purpose of ensuring that sensitive personal information is not inadvertently disclosed to an imposter or unauthorized third party. However, verification requirements should be proportionate and not used as a tool to delay or frustrate legitimate requests. For current employees, verification might be accomplished through existing organizational authentication methods. For former employees, verification might involve confirming details known to the individual from their period of employment or requesting government-issued identification. Once identity is verified, the organization should acknowledge receipt of the request in writing, provide the requester with an expected timeline for response, and immediately begin the process of gathering responsive records.

The response to an access request should provide the individual with copies of documents containing their personal information or, where the information is not recorded in document form, a meaningful summary of the information held. Organizations must explain how the information has been or is being used and identify any parties to whom the information has been disclosed in the year preceding the request. If any information is withheld pursuant to an exception, the organization should identify that information has been withheld and the general basis for withholding, without revealing the content of the withheld information.

Consider the situation faced by Clearwater Technical Services, a technology consulting firm with forty-seven employees operating from offices in Calgary and Edmonton. In November of the previous year, the organization received a comprehensive access request from a former employee who had worked as a senior software developer before her employment was terminated eight months earlier. The termination had occurred following a prolonged period of performance management that included multiple written warnings, a performance improvement plan, and ultimately a decision to end the employment relationship. The former employee submitted her access request by email to the company's general information address, stating that she wanted copies of all documents and information the company held about her, including but not limited to her personnel file, all emails referencing her, all meeting notes involving discussions about her, and any investigation files related to complaints she had made about her former manager.

The email sat in the general inbox for four days before being forwarded to the human resources manager, who recognized it as an access request. The human resources manager attempted to gather records from the personnel file, which was maintained in paper form in a locked cabinet, and from the electronic human resources information system. She contacted the former employee's direct manager to request any records he might be holding, and he produced a folder containing handwritten notes from several performance meetings plus printed copies of emails he considered relevant to the performance management process. Information technology was asked to preserve and produce the former employee's email account, which had been deactivated but not yet deleted following termination. The payroll manager produced records from the payroll system. The process took longer than anticipated because the human resources manager was managing multiple priorities and had never responded to a formal access request before.

On day twenty-eight of the thirty-day timeline, the human resources manager realized she had not collected records related to the workplace investigation. Six months before her termination, the former employee had filed a formal harassment complaint against her manager, alleging that his performance management approach was discriminatory and retaliatory. The company had retained an external investigator who produced a comprehensive report concluding that the allegations were not substantiated. The investigation file contained the complaint, interview notes from multiple witnesses, documents submitted by the complainant, documents submitted by the respondent manager, and the final investigation report. The human resources manager was uncertain whether this material needed to be produced and, if so, how to handle the portions containing personal information about other employees who had participated as witnesses.

Faced with an imminent deadline and unresolved questions, the company requested a fifteen-day extension, providing written notice to the former employee. During the extension period, the organization engaged a privacy consultant to assist with the response. The consultant reviewed the gathered records, identified additional material that should have been collected including GPS data from a company vehicle the employee had used and internet browsing records that had been retained by the information technology department, and developed a redaction protocol for the investigation file. The final response package included over four hundred pages of documents plus electronic data, with consistent redactions applied to third-party personal information and solicitor-client communications between the company and its employment lawyer clearly withheld pursuant to the applicable exception.

This situation illustrates several important realities about employee access rights. First, organizations must have systems that recognize access requests immediately upon receipt and route them to the appropriate individual for response. The four-day delay in this case could have been catastrophic had the timeline been even tighter. Second, the scope of personal information holdings is frequently broader than organizations initially recognize, and a systematic approach to identifying all repositories of personal information is essential. Third, the complexity of responding to access requests, particularly those involving investigation files or records containing information about multiple individuals, often requires expertise that may not exist in-house. Fourth, the thirty-day timeline is demanding, and organizations should not wait until a request arrives to develop their response procedures.

The failure to respond appropriately to an access request exposes organizations to regulatory and reputational risk. Privacy commissioners across Canadian jurisdictions have the authority to investigate complaints from individuals who believe their access rights have been denied or improperly limited. Findings against organizations can result in orders requiring disclosure, public reports that damage organizational reputation, and in some jurisdictions, administrative monetary penalties. Beyond regulatory risk, employee access requests often arise in contexts where the employment relationship is already strained or has ended badly. The manner in which an organization responds to an access request can influence whether disputes escalate to formal complaints, civil litigation, or human rights applications. A professional, complete, and timely response demonstrates organizational integrity and reduces the risk that the access request becomes the foundation for broader complaints.

Organizations should establish clear written procedures for responding to employee access requests that identify the individual or function responsible for coordinating responses, establish internal timelines that allow sufficient time for gathering and reviewing records before the legislative deadline arrives, create protocols for verifying requester identity, provide guidance on managing records that contain third-party personal information, document exceptions that may apply to certain categories of records, and establish quality review processes to ensure completeness and consistency. These procedures should be communicated to managers and supervisors who may receive access requests directly or who hold records about employees in their own files. Training should emphasize that handwritten notes, informal emails, and personal file copies are subject to production just as much as formal documents maintained by human resources.

Employers should also consider how records management practices affect the ability to respond to access requests. Organizations that retain excessive records, maintain inconsistent filing systems, or fail to implement systematic retention and destruction schedules create enormous burdens when access requests arrive. Conversely, organizations that destroy records prematurely may find themselves unable to demonstrate compliance with other legal obligations or to defend against claims arising from former employees. The balance requires thoughtful retention policies that align with legal requirements, business needs, and privacy principles including the requirement to destroy personal information once it is no longer required for the purpose for which it was collected.

Quebec's distinct approach to privacy in employment requires specific attention from organizations operating in that province. The modernization of Quebec's private sector privacy legislation has introduced enhanced requirements for transparency, consent, and individual rights that exceed the requirements under federal law and the legislation of other provinces. Organizations operating in Quebec must be particularly attentive to the specific requirements of that framework when developing access request response procedures.

The right of access is accompanied by a right of correction. When an employee or former employee reviews the personal information an organization holds about them and believes that information is inaccurate or incomplete, they have the right to request correction. Organizations must investigate such requests and, where the information is determined to be inaccurate, make the necessary corrections and notify any third parties to whom the inaccurate information was disclosed in the preceding year. Where the organization disagrees with the requested correction and declines to make changes, the individual has the right to have their disagreement noted in the file. This correction right ensures that the access right has practical value, allowing individuals not only to see what information is held but to ensure its accuracy.

Employers preparing to handle access requests should ask themselves several practical questions. Does the organization have a clear designated point of contact for privacy matters who would receive and coordinate responses to access requests? Has the organization conducted a comprehensive inventory of locations, systems, and formats in which employee personal information is held? Are managers and supervisors aware that their personal notes and files about employees are subject to access requests? Does the organization have template documents for acknowledging receipt of requests, verifying identity, providing extension notices, and delivering final responses? Has the organization identified categories of information that might be subject to exceptions and documented the basis for those determinations? Are retention policies clear, consistently applied, and documented so that the organization can demonstrate what records should exist for any particular time period? These questions form the foundation of access request readiness.

Ultimately, employee access rights reflect a fundamental principle of fairness in the employment relationship. Employers collect and maintain extensive information about workers, information that can profoundly affect their careers, their livelihoods, and their reputations. The right of access allows employees to understand what information exists about them, to ensure its accuracy, and to know how it has been used. For employers, respecting access rights is not merely a matter of legal compliance but an expression of the transparent, accountable approach to employment relationships that characterizes well-managed organizations. When access requests arrive, they present an opportunity to demonstrate integrity, build trust, and ensure that the organization's records reflect the truth of the employment relationship. Approached with this mindset, employee access requests become a manageable aspect of sound human resources practice rather than an adversarial burden to be minimized. The organizations that develop clear processes, train their people, and respond professionally to access requests protect themselves from regulatory risk while honoring the legitimate interests of the individuals who contribute their labor and their personal information to the enterprise.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options