Canadian Privacy Laws (Part 3): British Columbia Privacy Laws
British Columbia is one of the provinces that has its own private-sector privacy law. That makes it different from Ontario, where PIPEDA is still the main law for most private businesses.
In B.C., the key law for private organizations is the:
- Personal Information Protection Act (PIPA).
- Freedom of Information and Protection of Privacy Act (FIPPA).
Together, these laws set rules for how organizations and public bodies collect, use, share, protect, and give access to personal information.
Here are the Main British Columbia Privacy Laws to Understand.
PIPA: B.C.’s Private-Sector Privacy Law
The Personal Information Protection Act (PIPA) applies to private-sector and not-for-profit organizations in British Columbia.
Who it applies to: businesses, charities, associations, professional practices, independent schools, and other private organizations that collect, use, or disclose personal information.
What it does: PIPA sets rules for how organizations collect, use, share, protect, and give access to personal information. Organizations are expected to use personal information for reasonable purposes, usually get consent, explain why information is being collected, and protect it properly.
Why businesses should care: B.C. has its own private-sector privacy law, so businesses operating in the province need to understand PIPA, not just PIPEDA. Privacy should be part of how customer data, employee information, marketing lists, online forms, service records, and vendor systems are managed.
FIPPA: B.C.’s Public-Sector Privacy Law
The Freedom of Information and Protection of Privacy Act (FIPPA) applies to public bodies in British Columbia.
Who it applies to: provincial ministries, government agencies, Crown corporations, municipalities, public schools, universities, colleges, health authorities, and other public-sector organizations.
What it does: FIPPA sets rules for how public bodies collect, use, disclose, retain, and protect personal information. It also gives people the right to request access to records held by public bodies, including their own personal information.
Why businesses should care: If your company works with public-sector clients in B.C., FIPPA may influence what those clients expect from you. This could show up in contracts, security requirements, data storage expectations, access controls, breach response, or privacy impact assessments.
How B.C. Fits with PIPEDA
The biggest difference between B.C. and some other provinces is that B.C. has its own private-sector privacy law.
For many B.C. businesses, PIPA is the main law to understand for local commercial activity. PIPEDA may still matter when personal information crosses provincial or national borders, or when the organization is federally regulated.
That means businesses should not assume one law covers every situation. The right privacy framework depends on where the organization operates, what type of data it handles, and whether the activity is local, national, or international.
Why This Matters for Your Business
If your business operates in British Columbia, serves B.C. customers, or supports B.C. organizations, privacy responsibilities may look different than they do in Ontario.
A good starting point is to know what personal information you collect, why you collect it, where it is stored, who can access it, and how long it is kept. It is also important to have clear consent practices, strong safeguards, documented privacy policies, and a plan for responding to privacy incidents.
In short, British Columbia has a more complete provincial privacy framework than some provinces because it regulates both private organizations and public bodies.
For businesses, that means privacy compliance is not only about following federal rules. It is also about understanding B.C.’s PIPA and FIPPA requirements and building privacy into everyday operations.
A Seven Part Series on Privacy Laws in Canada
Stay tuned for the next entry in our series, where we will look at how privacy laws differ across the Canadian provinces.
- Part 1: Federal Laws: Unpack overarching federal frameworks like PIPEDA to establish baseline data protection standards.
- Part 2: Provincial Laws – Ontario: Navigate local corporate privacy standards and sector-specific regulations unique to Ontario.
- Part 3: Provincial Laws – British Columbia: Examine B.C.’s distinct statutes and strict regional rules regarding data residency.
- Part 4: Provincial Laws – Alberta: Review Alberta’s PIPA framework for private sector accountability and local consent rules.
- Part 5: Provincial Laws – Nova Scotia: Learn how Nova Scotia’s regional frameworks shape commercial privacy and administrative accountability.
- Part 6: Provincial Laws – Quebec: Dive into Quebec’s Law 25, focusing on strict corporate transparency and severe penalties.
- Part 7: Provincial Laws – Manitoba: Map out Manitoba’s legislative landscape to keep regional digital operations compliant.
