Resources
PIPEDA and Your Old Hard Drives: What You Need to...
- PIPEDA requires Canadian organizations to destroy personal information that is no longer needed for its original purpose.
- ]Simply deleting files, formatting drives, or sending equipment to a recycler is not sufficient under the law.
- The Privacy Commissioner can investigate complaints, audit disposal practices, and impose fines of up to $100,000 per violation.
- Organizations must use disposal methods "appropriate to the sensitivity" of the data — and must be able to prove it.
- This article explains exactly what PIPEDA requires, what can go wrong, and how to build a compliant disposal process.