Anonymised, illustrative composite. A former client asked for a copy of their file. PIPEDA's access-request clock, not the brokerage's own sense of urgency, set the deadline.
At a glance
A former seller client, whose sale had closed three years earlier, emailed the brokerage asking for “a complete copy of everything in my file” — notes, correspondence, the comparative market analysis, and any financial information on record. The email landed in a general inquiries inbox and sat there.
The client did not say why they wanted it. Nothing about the request required an explanation — under PIPEDA’s meaningful-consent framework, individual access is a right attached to the information itself, not a favour conditioned on the requester’s reason for asking.
Personal information collected in the course of a real estate transaction is squarely covered by PIPEDA, and an individual’s right to access it does not expire when the file closes or the client relationship ends. The request sat unactioned for 24 days before anyone internally recognized it as a formal access request rather than a routine customer-service email, and began pulling the file together.
PIPEDA sets a hard clock on the response, not a best-efforts target. Section 8(3) of the Act requires an organization to respond “with due diligence and in any case not later than thirty days after receipt of the request.” The request had been received on day 0 — not on the day someone finally noticed it.
The request sat for 24 days before anyone began assembling the file. Once flagged, staff located and compiled the notes, correspondence, and CMA documents, and the response was sent on day 29 of the 30-day window — a single day of margin left. Under PIPEDA section 8(4), an organization may extend the deadline by up to 30 additional days where meeting the original one would unreasonably interfere with its activities — but only if the individual is notified of the extension, with reasons, within the original 30 days. No such notice was ever sent here, because nobody had logged the clock as running until it was nearly out.
The obligation is unambiguous in the statute itself. Section 8(5) states plainly: failure to respond within the time limit “is deemed to be a refusal to give access.” That deeming provision applies regardless of whether the brokerage ever intended to withhold anything — a late response, even one that ultimately hands over the complete file, is treated in law the same way as an outright refusal would be.
The extension route in section 8(4) exists precisely for a file this old and this involved, but it has its own precondition: notice to the individual, with reasons, inside the original 30 days. Missing that notice window closes the extension option entirely, leaving only the original 30-day deadline in force.
The response went out on day 29, inside the window, with the full file the client had asked for. The deemed-refusal risk in section 8(5) never actually crystallized — but the margin for error had been a single day, on a request that had genuinely been logged and available from day 0.
The brokerage changed one thing afterward: any email that looked like a data-access request, from a current or former client, would be date-stamped and forwarded to the privacy-compliance contact the same day, rather than left for whoever next checked the general inbox to recognize it for what it was.
For the underlying right, see the personal information glossary entry, and for the consent framework that governs what the brokerage was allowed to collect in the first place, the meaningful consent glossary entry. For a related file-security failure involving the same client records, see a lost laptop full of client files.
The deeming provision is what makes this expensive to get casually wrong: it does not require proof that anything was actually withheld, only that the 30-day clock ran out. A brokerage that responded on day 31 with the exact same complete file would, in law, have already committed a deemed refusal on day 30 — a purely procedural default, with no connection to whether the client was ever going to get everything they asked for. The cost of missing the deadline is not measured by what was withheld; it is triggered by the date alone.
The tell was in how the clock started: PIPEDA’s 30 days run from receipt of the request, not from whenever someone internally identifies it as a formal access request. An email sitting in a general inbox for 24 days before anyone recognizes what it is has already burned four-fifths of the available time — the fix is logging the receipt date the moment a request like this arrives, not once it gets forwarded to the right desk.
A 30-minute call is enough to tell you whether AI pays for itself here.