Antoine Guilmain
Partner
Co-leader, National Cybersecurity & Data Protection Group
Article
3
On December 1, 2025, the Office of the Privacy Commissioner of Canada (the “OPC”) published the findings of an investigation into the privacy practices of an organization operating a program to resell electronic devices returned by its customers.
The OPC's findings are highly instructive as to the scope of the obligations under the Personal Information Protection and Electronic Documents Act (“PIPEDA”). They offer particularly relevant insights for organizations that handle, refurbish, or resell electronic devices that may contain personal information belonging to former users.
The organization in question operated a program that allowed customers to return laptops, which were then refurbished and resold. Such a program poses obvious risks to the protection of personal information, as these devices often contain residual data relating to their former users.
Following a complaint alleging insufficient wiping of returned devices, the OPC launched an investigation into the organization's internal practices. The investigation found that the organization had not implemented adequate measures to protect personal information from unauthorized access or disclosure, particularly due to inadequate internal policies and training, and the absence of effective control mechanisms.
The investigation clarifies the scope of Principles 4.7.1 and 4.7.3 of PIPEDA. These provisions establish that organizations must have security measures in place, whether physical, organizational, or technological, to protect personal information from loss, theft, or unauthorized disclosure, regardless of the form in which it is stored.
In its conclusions, the OPC states that, to be considered adequate under principles 4.7.1 and 4.7.3, wiping procedures must comply with the device manufacturer's guidelines for resetting and wiping data.
Therefore, any organization that holds used electronic devices, whether as part of a take-back program, refurbishment program, or otherwise, must ensure that they are wiped in accordance with the manufacturer's instructions. This requirement is intended to reduce the risk of personal information being recovered by unauthorized parties.
The OPC specifies that organizations must adopt and make available to their staff clear, consistent, and standardized instructions on the procedure to follow for wiping returned devices.
In this case, the investigation revealed that the organization's internal practices did not ensure that reset procedures were consistently applied in accordance with the manufacturer's guidelines. This situation was notably due to contradictory internal policies, which did not include any clear requirements for employees to apply the data deletion and reset procedures provided by the manufacturer.
Furthermore, the OPC emphasizes that organizations have an obligation to provide their staff with adequate training so that they can properly perform all technical tasks related to the deletion of personal information.
During the investigation, it was found that the training offered by the organization was not systematically provided to technical staff. In addition, according to the OPC, the training material made available to managers was high level and lacking details as it did not specify the concrete steps to be taken to clean a device or the means to verify that the deletion had been effectively carried out.
Finally, the OPC emphasizes the need for organizations to actively monitor compliance with the policies they adopt. For this purpose, it recommends, among other things:
These recommendations highlight the obligation for organizations handling electronic devices containing the personal information of former users to be diligent and responsible in their internal practices, in particular by adopting mechanisms to monitor the application of procedures and compliance with requirements.
If you have any questions about the OPC recommendations or your organization’s policies, please contact the authors or a member of our Data Protection and Cyber Security team.
NOT LEGAL ADVICE. Information made available on this website in any form is for information purposes only. It is not, and should not be taken as, legal advice. You should not rely on, or take or fail to take any action based upon this information. Never disregard professional legal advice or delay in seeking legal advice because of something you have read on this website. Gowling WLG professionals will be pleased to discuss resolutions to specific legal concerns you may have.
Gowling WLG is an international law firm comprising the members of Gowling WLG International Limited, an English Company Limited by Guarantee, and their respective affiliates. Each member and affiliate is an autonomous and independent entity. Gowling WLG International Limited promotes, facilitates and co-ordinates the activities of its members but does not itself provide services to clients. Our structure is explained in more detail on our Legal Information page.
© 2026 Gowling WLG All rights reserved.