Overview
The Personal Information Protection Act came into force on January 1, 2004 and covers almost every private-sector organization in British Columbia, including non-profits. It's consent based. Organizations need consent to collect, use, or disclose personal information unless the Act allows otherwise, and they may do so only for purposes a reasonable person would consider appropriate. Employee personal information has its own rules. Section 34 requires reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks.
The Act still doesn't require organizations to report privacy breaches to the Commissioner or to notify affected people. The OIPC treats reporting as a best practice and has called on government to amend PIPA to make it mandatory. Public bodies are in a different position. Under the Freedom of Information and Protection of Privacy Act, a public body must notify affected individuals and the Commissioner of breaches that could reasonably be expected to result in significant harm. Many BC organizations also notify under PIPEDA when cross-border or federal activity is involved.
A special committee of the legislature reviewed PIPA and released its report, Modernizing British Columbia's Private Sector Privacy Law, in December 2021. No amending bill has followed. The legislature was dissolved on September 22, 2026 for a provincial general election, so no bill is before it as of October 11, 2026. Offences under the Act carry fines of up to $10,000 for individuals and $100,000 for other persons.
Who it applies to in Canada
Private-sector organizations in British Columbia, including businesses, non-profits, charities, trade unions, and political parties, for both customer and employee personal information. Federally regulated businesses and public bodies fall under other laws.
BC PIPA is recognized as substantially similar to PIPEDA, so it applies instead of the federal law for activity within the province. Unlike PIPEDA, Alberta PIPA, and Quebec's law, it still has no mandatory breach reporting, which matters for national incident response plans.
Controls at a glance
The Act is organized in parts covering policies, consent, collection, use, disclosure, access and correction, care of information, and the Commissioner's powers.
Policies and accountability
- Designate someone responsible for compliance
- Develop policies and practices to meet the Act
- Set up a complaint process
- Make policy information available on request
Consent
- Get consent unless the Act allows otherwise
- Use implicit consent only where it's reasonable
- Allow withdrawal of consent on reasonable notice
- Don't require more consent than a product needs
Collection, use, and disclosure
- Tell people the purpose at or before collection
- Limit purposes to what a reasonable person expects
- Use and disclose only for those purposes
- Apply listed exceptions for no-consent handling
Employee personal information
- Limit to establishing, managing, or ending employment
- Give notice before collecting without consent
- Keep collection reasonable for the purpose
Access and correction
- Respond to access requests within 30 days
- Explain how information was used and disclosed
- Correct errors or annotate the record
Care of personal information
- Make reasonable security arrangements
- Keep information accurate and complete
- Keep information used in a decision for at least one year
- Destroy or de-identify information no longer needed
Breach response (best practice)
- Contain the breach and preserve evidence
- Assess the risk of harm
- Notify affected people where it can reduce harm
- Report to the OIPC voluntarily
- Review and prevent recurrence
Certification and assessment
There is no certification. The OIPC investigates complaints, can audit organizations, holds inquiries, and issues binding orders. Individuals can sue for damages once an order or conviction is final.
Dates to know
- 2004-01-01
- Personal Information Protection Act comes into force
- 2021-12
- Special committee releases its report, Modernizing British Columbia's Private Sector Privacy Law
- 2026-09-22
- Legislative Assembly dissolved for a provincial general election
Resources
Official texts and free tools for BC PIPA. Links open the publisher’s site.
- Personal Information Protection Act (SBC 2003, c. 63), BC Laws
- Office of the Information and Privacy Commissioner for British Columbia, OIPC BC
- Breach notification webform for representatives of organizations and public bodies, OIPC BCtool
- Privacy breach quick reference guide for small and medium-sized businesses, OIPC BCguidance
Need help? Browse the directory or read the guides.
References
- Personal Information Protection Act (SBC 2003, c. 63), BC Laws
- Breach notification webform for representatives of organizations and public bodies, OIPC BC
- Privacy breach quick reference guide for small and medium-sized businesses, OIPC BC
- Special Committee to Review the Personal Information Protection Act, Legislative Assembly of British Columbia
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.