home / frameworks / bc-pipa

// Canadian privacy and cyber law

Personal Information Protection Act (British Columbia)

British Columbia's Personal Information Protection Act sets consent, access, and security rules for private-sector organizations in the province. As of October 2026 it has no mandatory breach notification, although the OIPC strongly recommends reporting breaches that pose a risk of significant harm.

British Columbia

Overview

The Personal Information Protection Act came into force on January 1, 2004 and covers almost every private-sector organization in British Columbia, including non-profits. It's consent based. Organizations need consent to collect, use, or disclose personal information unless the Act allows otherwise, and they may do so only for purposes a reasonable person would consider appropriate. Employee personal information has its own rules. Section 34 requires reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks.

The Act still doesn't require organizations to report privacy breaches to the Commissioner or to notify affected people. The OIPC treats reporting as a best practice and has called on government to amend PIPA to make it mandatory. Public bodies are in a different position. Under the Freedom of Information and Protection of Privacy Act, a public body must notify affected individuals and the Commissioner of breaches that could reasonably be expected to result in significant harm. Many BC organizations also notify under PIPEDA when cross-border or federal activity is involved.

A special committee of the legislature reviewed PIPA and released its report, Modernizing British Columbia's Private Sector Privacy Law, in December 2021. No amending bill has followed. The legislature was dissolved on September 22, 2026 for a provincial general election, so no bill is before it as of October 11, 2026. Offences under the Act carry fines of up to $10,000 for individuals and $100,000 for other persons.

Who it applies to in Canada

Private-sector organizations in British Columbia, including businesses, non-profits, charities, trade unions, and political parties, for both customer and employee personal information. Federally regulated businesses and public bodies fall under other laws.

BC PIPA is recognized as substantially similar to PIPEDA, so it applies instead of the federal law for activity within the province. Unlike PIPEDA, Alberta PIPA, and Quebec's law, it still has no mandatory breach reporting, which matters for national incident response plans.

Controls at a glance

The Act is organized in parts covering policies, consent, collection, use, disclosure, access and correction, care of information, and the Commissioner's powers.

Policies and accountability

  • Designate someone responsible for compliance
  • Develop policies and practices to meet the Act
  • Set up a complaint process
  • Make policy information available on request

Consent

  • Get consent unless the Act allows otherwise
  • Use implicit consent only where it's reasonable
  • Allow withdrawal of consent on reasonable notice
  • Don't require more consent than a product needs

Collection, use, and disclosure

  • Tell people the purpose at or before collection
  • Limit purposes to what a reasonable person expects
  • Use and disclose only for those purposes
  • Apply listed exceptions for no-consent handling

Employee personal information

  • Limit to establishing, managing, or ending employment
  • Give notice before collecting without consent
  • Keep collection reasonable for the purpose

Access and correction

  • Respond to access requests within 30 days
  • Explain how information was used and disclosed
  • Correct errors or annotate the record

Care of personal information

  • Make reasonable security arrangements
  • Keep information accurate and complete
  • Keep information used in a decision for at least one year
  • Destroy or de-identify information no longer needed

Breach response (best practice)

  • Contain the breach and preserve evidence
  • Assess the risk of harm
  • Notify affected people where it can reduce harm
  • Report to the OIPC voluntarily
  • Review and prevent recurrence

Certification and assessment

There is no certification. The OIPC investigates complaints, can audit organizations, holds inquiries, and issues binding orders. Individuals can sue for damages once an order or conviction is final.

Dates to know

2004-01-01
Personal Information Protection Act comes into force
2021-12
Special committee releases its report, Modernizing British Columbia's Private Sector Privacy Law
2026-09-22
Legislative Assembly dissolved for a provincial general election

Resources

Official texts and free tools for BC PIPA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Personal Information Protection Act (SBC 2003, c. 63), BC Laws
  2. Breach notification webform for representatives of organizations and public bodies, OIPC BC
  3. Privacy breach quick reference guide for small and medium-sized businesses, OIPC BC
  4. Special Committee to Review the Personal Information Protection Act, Legislative Assembly of British Columbia