Resources

PIPEDA hard drive data disposal compliance guide

PIPEDA and Your Old Hard Drives: What You Need to...


  • PIPEDA requires Canadian organizations to destroy personal information that is no longer needed for its original purpose.
  • ]Simply deleting files, formatting drives, or sending equipment to a recycler is not sufficient under the law.
  • The Privacy Commissioner can investigate complaints, audit disposal practices, and impose fines of up to $100,000 per violation.
  • Organizations must use disposal methods "appropriate to the sensitivity" of the data — and must be able to prove it.
  • This article explains exactly what PIPEDA requires, what can go wrong, and how to build a compliant disposal process.
Continue
PIPEDA data destruction