On December 1, 2025, the Office of the Privacy Commissioner of Canada (the “OPC”) published the findings of an investigation into the privacy practices of an organization operating a program to resell electronic devices returned by its customers.

The OPC's findings are highly instructive as to the scope of the obligations under the Personal Information Protection and Electronic Documents Act (“PIPEDA”). They offer particularly relevant insights for organizations that handle, refurbish, or resell electronic devices that may contain personal information belonging to former users.

Context

The organization in question operated a program that allowed customers to return laptops, which were then refurbished and resold. Such a program poses obvious risks to the protection of personal information, as these devices often contain residual data relating to their former users.

Following a complaint alleging insufficient wiping of returned devices, the OPC launched an investigation into the organization's internal practices. The investigation found that the organization had not implemented adequate measures to protect personal information from unauthorized access or disclosure, particularly due to inadequate internal policies and training, and the absence of effective control mechanisms.

Organizations' obligations

The investigation clarifies the scope of Principles 4.7.1 and 4.7.3 of PIPEDA. These provisions establish that organizations must have security measures in place, whether physical, organizational, or technological, to protect personal information from loss, theft, or unauthorized disclosure, regardless of the form in which it is stored.

Mandatory reset

In its conclusions, the OPC states that, to be considered adequate under principles 4.7.1 and 4.7.3, wiping procedures must comply with the device manufacturer's guidelines for resetting and wiping data.

Therefore, any organization that holds used electronic devices, whether as part of a take-back program, refurbishment program, or otherwise, must ensure that they are wiped in accordance with the manufacturer's instructions. This requirement is intended to reduce the risk of personal information being recovered by unauthorized parties.

Clear and precise internal policies and procedures

The OPC specifies that organizations must adopt and make available to their staff clear, consistent, and standardized instructions on the procedure to follow for wiping returned devices.

In this case, the investigation revealed that the organization's internal practices did not ensure that reset procedures were consistently applied in accordance with the manufacturer's guidelines. This situation was notably due to contradictory internal policies, which did not include any clear requirements for employees to apply the data deletion and reset procedures provided by the manufacturer.

Mandatory and sufficient training

Furthermore, the OPC emphasizes that organizations have an obligation to provide their staff with adequate training so that they can properly perform all technical tasks related to the deletion of personal information.

During the investigation, it was found that the training offered by the organization was not systematically provided to technical staff. In addition, according to the OPC, the training material made available to managers was high level and lacking details as it did not specify the concrete steps to be taken to clean a device or the means to verify that the deletion had been effectively carried out.

Ensure compliance with adopted policies

Finally, the OPC emphasizes the need for organizations to actively monitor compliance with the policies they adopt. For this purpose, it recommends, among other things:

  • Adopt an internal procedure to ensure that only employees who have received the required training clean the devices.
  • Appoint an independent third-party to conduct an annual spot check of devices returned under the electronic device resale program.

These recommendations highlight the obligation for organizations handling electronic devices containing the personal information of former users to be diligent and responsible in their internal practices, in particular by adopting mechanisms to monitor the application of procedures and compliance with requirements.

If you have any questions about the OPC recommendations or your organization’s policies, please contact the authors or a member of our Data Protection and Cyber Security team.