When a Client Withdraws Consent
The request is the easy part. What you do with records you have already relied on is where most practices get stuck.
A client asking you to stop contacting them, or to delete their record, produces the same administrative reaction in most practices: a small delay, a request for the details, and then a quiet period while somebody works out what they are allowed to delete. That delay is the part worth fixing, because the obligation to respond is the one that does not pause.
Respond, then work out what you can do
Acknowledging the request promptly costs nothing and is the part everybody gets right by accident. The harder half is the question that follows: what happens to a record you have already used?
The honest answer is that some of it stays. You cannot delete the clinical record of a treatment you delivered. Invoicing and payment records have their own retention obligations, and they outlive the therapeutic relationship by years. What you can normally do is stop marketing to that person, stop sending them reminders, and remove them from any list you contact.
Confirm who you are talking to
This is the step most likely to be skipped and least safe to skip. A request to delete a record has to come from the person whose record it is, or from someone lawfully entitled to ask on their behalf, such as a legal representative or an executor. Where a third party is acting, you are owed evidence of that authority.
Confirming identity before releasing anything is not a bureaucratic habit. It is the control that stops the worst outcome in this area, which is destroying a real client's record because a stranger asked for it.
Withdrawal and refusal are different things
Withdrawing consent to future contact is straightforward and should be honoured immediately. Deleting a record is a separate question governed by retention law and your professional obligations, and declining it is a legitimate outcome rather than a failure.
If you do decline, tell the client that you have declined and why. A silent refusal is the version that generates complaints.
What a consent record should actually show
This is where most systems fall short, and the reason is worth naming: a client who declines something today has, in most software, silently overwritten the record that they agreed to it yesterday. The grant and its date are gone, and what remains is a refusal with no history.
A consent record needs to keep both. When did they agree, when did they withdraw, and what was withdrawn. That is not only useful for you: it is the record that lets you answer, years later, what you were permitted to do with their information and when.
Withdrawing consent should also be recorded rather than deleted. If a withdrawal itself could be removed, then the record of the withdrawal disappears with it, and you are left having acted correctly with nothing to show for it.
What to put in place this month
Write down three things: who may authorise a deletion and how you confirm it, what you can and cannot delete and on what authority, and how a client is told when you decline. Put them where your front desk can reach them, because the request will arrive on a busy afternoon rather than at a convenient moment.
The Office of the Privacy Commissioner of Canada sets out the principles in its guidance on individual privacy rights, and what a breach means for your practice in its breach guidance. Both are worth an afternoon before you need them.