Back to Blog
Compliance
4 min read

BC PIPA: Privacy Obligations for Private Organisations in British Columbia

BC PIPA covers employee information in a way PIPEDA does not, and its breach rules changed. What private organisations in British Columbia owe.

GuardsArm Team

Security Experts

September 25, 2026

BC PIPA compliance for private organisations

British Columbia's Personal Information Protection Act governs private-sector organisations in the province. It is broadly comparable to PIPEDA, and organisations often assume compliance with one delivers the other. Two differences make that assumption expensive.

Employees are covered
Unlike PIPEDA for provincially regulated employers
Notify purposes in advance
Monitoring without prior notice is the common finding
Minimum retention exists
Decision-related information must be kept, not purged

Difference one: employee personal information is in scope

PIPEDA covers employee information only at federally regulated employers. BC PIPA has a dedicated concept of employee personal information and brings every provincially regulated employer in the province within scope.

The Act permits collection, use and disclosure of employee personal information without consent where it is reasonable for establishing, managing or terminating the employment relationship — but requires that you notify the employee of the purposes beforehand.

PracticeWhat BC PIPA expects
Monitoring software on work devicesPurpose notified in advance; reasonable in scope
Background checksNotified; limited to what the role justifies
Location tracking in vehiclesNotified; reasonable for the management purpose
Access to employee mailboxes during investigationsPurpose grounded in the employment relationship

"Reasonable" does the work here, and it is assessed objectively. Monitoring deployed broadly because a tool made it easy tends to fail that test. Employers arriving from a PIPEDA mindset frequently have no notification at all, because the obligation never applied to them before.


Difference two: the second regime you are also in

BC PIPA does not displace PIPEDA for information crossing a provincial or national border in commercial activity, or for federally regulated businesses. A BC company serving customers in Alberta operates under both.

Which regime applies in British ColumbiaBC PIPA governs commercial activity and employee information within the province. PIPEDA continues to apply to cross-border flows and federally regulated businesses.Commercial activity inside BCBC PIPA governsEmployee information, provincial employerBC PIPA governs — PIPEDA would notPersonal information crossing a borderPIPEDA also appliesFederally regulated businessPIPEDA governs regardless of location
Most organisations of any size are in both at once.

The core obligations

Consent may be express, implied or deemed depending on sensitivity and context, with opt-out consent available in defined circumstances. Sensitive information pushes you toward express consent.

A privacy officer must be designated, and their contact information made available on request.

Reasonable security arrangements must protect personal information against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. Note that unauthorised disposal is named — losing information is a breach, not merely an operational failure.

Access and correction rights apply, with a statutory response timeline.

Retention has a specific BC wrinkle: where personal information has been used to make a decision that directly affects an individual, it must be retained for a minimum period so the individual has a reasonable opportunity to access it. Aggressive deletion schedules can breach the Act in the other direction.

Deleting too early can breach the Act
Where personal information was used to make a decision directly affecting someone, BC PIPA requires it to be kept long enough for them to request access. A retention policy tuned only for minimisation can put you offside in the opposite direction from the usual one.

Breach obligations

Breach notification rules under BC PIPA have been strengthened, bringing the province closer to the harm-based reporting model used federally and in Alberta. Organisations should confirm the current notification thresholds and timelines that apply to them, and in the meantime build the capability those rules require:

  • An incident register with a row per incident
  • A documented harm assessment method, applied consistently
  • Notification templates ready before you need them
  • Enough logging to establish what was affected

Every one of those is worth having regardless of the precise threshold, and all four are what an organisation is missing when an incident finds it unprepared. See the first 72 hours.


Service providers and outsourcing

BC PIPA does not let you outsource accountability. Where a service provider processes personal information on your behalf, you remain responsible for it, and the Act's safeguard duty extends to information in their hands.

What that requires contractually:

  • Purpose limitation — the provider uses the information only for your purposes, not their own product improvement
  • Sub-processor visibility, with the right to object
  • Security obligations at least equal to your own
  • Breach notification to you, fast enough for you to meet your obligation
  • Return or destruction at termination, evidenced

Where a provider stores information outside Canada, that is not prohibited, but it is a factor in whether your arrangements are reasonable, and it is a disclosure your privacy notice should reflect. Public bodies in BC face tighter constraints here than private organisations do, so guidance written for the public sector does not transfer directly.


Where to start

If you employ people in British Columbia, check whether you have ever notified them of the purposes for which you collect their personal information. For most organisations that have not looked at PIPA specifically, the answer is no, and it is the most likely finding against you.

GuardsArm supports BC organisations with PIPA assessments and security programmes. See PIPA compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.