📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

What is BC PIPA

What is BC PIPA (Personal Information Protection Act)?

BC PIPA (the Personal Information Protection Act) is British Columbia's provincial private-sector privacy law. Designated substantially similar to PIPEDA, it applies to private-sector organizations operating in BC. Breach reporting under it is still voluntary, although the OIPC expects organizations to notify people at real risk of significant harm. It is enforced by the Office of the Information and Privacy Commissioner for British Columbia.

Map your BC PIPA controls See the core components

Substantially similar to PIPEDA · breach reporting voluntary · distinct from FIPPA

Definition

BC PIPA (the Personal Information Protection Act) is British Columbia's provincial private-sector privacy law.

BC PIPA was enacted in 2003 and came into force on 1 January 2004. The federal government has designated it substantially similar to PIPEDA, so it applies to most private-sector activity in BC in place of PIPEDA. Federally regulated work (banks, telcos, airlines, inter-provincial transportation) remains subject to PIPEDA.

BC PIPA is built around the same Fair Information Principles as PIPEDA and Alberta PIPA, but is a separately enforced provincial statute. The Office of the Information and Privacy Commissioner for British Columbia administers the Act.

Unlike Alberta PIPA and PIPEDA, BC PIPA does not yet require organizations to report breaches. The BC OIPC has repeatedly asked for mandatory notification, and the breach notification requirement BC introduced on 1 February 2023 applies only to public bodies under FIPPA.

Core components

Reasonable purposes test

Collection, use, and disclosure must be for purposes a reasonable person would consider appropriate.

Consent

Express, implied, deemed, or opt-out depending on context. Sensitive information typically requires more explicit consent.

Privacy Officer

Each organization must designate a person accountable for compliance.

Breach notification: voluntary, but expected

BC PIPA does not require breach reporting, but the OIPC expects organizations to notify affected people and the OIPC when a breach creates a real risk of significant harm. Keeping a record of every breach is good practice.

Subject access rights

Individuals have rights of access and to challenge accuracy.

OIPC oversight

Investigations, orders, and inquiries are handled by the BC Office of the Information and Privacy Commissioner.

FIPPA distinction

BC PIPA is the private-sector law. BC public bodies are governed by the separate Freedom of Information and Protection of Privacy Act (FIPPA). The two laws have similar principles but distinct obligations.

Why it matters

For private-sector organizations operating in BC, BC PIPA (not PIPEDA) is the operative privacy law. MSPs based in BC or serving BC clients work primarily under BC PIPA.

Breach notification is the biggest gap in BC PIPA today: it is voluntary, and the OIPC has called for it to become mandatory. Organizations that build detection and notification now will not have to scramble if the law changes, and they already meet the Alberta PIPA and PIPEDA expectations that apply to clients in those jurisdictions.

For BC MSPs, the BC privacy regime stacks: BC PIPA for general private-sector work; the BC E-Health Act when the client interacts with provincial Health Information Banks; FIPPA for public-sector work; plus PIPEDA where federal-jurisdiction work is involved. Many MSP clients fall under more than one.

How Lavawall® helps with BC PIPA

Lavawall® includes BC PIPA as a first-class framework alongside PIPEDA, Alberta PIPA, and Quebec Law 25. The OIPC's breach guidance is mapped to the breach detection and notification workflow that M365 breach detection and identity-threat detection feed.

Lavawall® is hosted in Canada (AWS Montréal by default, moving to a Canadian-owned hosting provider in Vancouver in Q4 2026), so BC data does not leave Canada when stored on Lavawall® itself.

ThreeShield Information Security Corporation, the audit firm that built Lavawall®, supports BC clients on BC PIPA work in addition to its Alberta base. The BC PIPA control mapping follows the OIPC's current breach guidance. For BC MSPs, Lavawall® produces the safeguards evidence, breach-notification workflow, and breach record-keeping that BC procurement teams and the OIPC expect.

Start your BC PIPA control mapping →

Frequently asked

Is BC PIPA the same as PIPEDA?
No. PIPEDA is federal; BC PIPA is provincial. BC PIPA is designated substantially similar to PIPEDA but is separately enforced by the BC OIPC.
Is BC PIPA the same as FIPPA?
No. BC PIPA is the private-sector law. The Freedom of Information and Protection of Privacy Act (FIPPA) is the public-sector law for BC public bodies (government, health authorities, post-secondary institutions, etc.). They have related principles but distinct obligations.
Is breach notification mandatory under BC PIPA?
No. Breach reporting under BC PIPA is still voluntary. The mandatory breach notification that took effect in BC on 1 February 2023 applies to public bodies under FIPPA, not to private organizations under PIPA. Alberta PIPA and PIPEDA both require it, and the BC OIPC has asked for PIPA to follow.
When should you notify a breach under BC PIPA?
The OIPC's guidance uses a real risk of significant harm test. If a breach could seriously harm the people affected, the OIPC expects you to notify them and the OIPC promptly, even though BC PIPA does not yet require it.
Do BC MSPs need to comply with BC PIPA?
Yes. BC MSPs are themselves private-sector organizations and also handle personal information for clients. BC PIPA applies to both sets of activities.