.jpg)
The first call usually comes on a Friday afternoon. A staff member clicked a link, a vendor's server was encrypted, or a customer list turned up somewhere it should not be. Within hours, someone has to decide who must be told, what can be said, and what must be preserved.
Those decisions are governed by your data breach obligations in BC, and they are more nuanced than most business owners expect. British Columbia's private-sector privacy statute does not contain an express breach-reporting section. Federal law does. Which one applies to you, and how you handle the first few days, shapes your regulatory exposure and your class action risk for years.
This guide explains which statute governs your business, when notification is mandatory or expected, how the "real risk of significant harm" test works, and what a defensible response looks like.
In legal terms, a privacy breach is the loss of, unauthorized access to, or unauthorized collection, use, disclosure or disposal of personal information. Ransomware, phishing, a misdirected email and a lost laptop all qualify.
"Personal information" is defined broadly. Under the Personal Information Protection Act (BC) (PIPA), it means information about an identifiable individual, with carve-outs for business contact information and work product information.
Two practical points follow:
This is the first question to answer, because the notification rules differ sharply. Three statutes do most of the work.
PIPA governs how private-sector organizations collect, use and disclose personal information within British Columbia, including employee personal information. It is overseen by the Office of the Information and Privacy Commissioner for British Columbia (OIPC).
If you are a BC retailer, professional firm, contractor, clinic, technology company or non-profit, PIPA is likely your primary statute.
The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies in BC to federal works, undertakings and businesses, such as banks, telecommunications companies, airlines and interprovincial transport. It also applies to personal information that crosses provincial or national borders in the course of commercial activity.
Many BC businesses are subject to both regimes for different data flows. A Vancouver e-commerce company selling to customers across Canada should assume PIPEDA reaches at least part of its operations.
The Freedom of Information and Protection of Privacy Act (BC) (FIPPA) governs provincial public bodies: ministries, health authorities, municipalities, school districts and universities. Since February 1, 2023, FIPPA has required public bodies to notify affected individuals and the OIPC of privacy breaches that could reasonably be expected to cause significant harm.
This matters to private companies that serve the public sector. FIPPA requires a service provider's employees and associates who know of an unauthorized disclosure to report it to the public body immediately, and government contracts usually impose tighter reporting terms on top.
The answer depends entirely on which statute governs the data involved.
PIPA does not currently contain a mandatory breach-notification provision. As of October 2026, no amendment adding one has been introduced, and the 2026 privacy amendments passed in BC changed FIPPA, not PIPA.
That does not make silence a safe default. Section 34 of PIPA requires an organization to protect personal information in its custody or under its control by making reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification or disposal. Where notice would help affected people protect themselves, a failure to give it can be difficult to reconcile with that duty.
The OIPC accepts voluntary breach reports and publishes guidance on containment, risk assessment and notification. In practice, a timely voluntary report usually positions a BC organization better than a complaint-driven investigation that begins months later.
Section 10.1 of PIPEDA requires an organization to report a breach of security safeguards to the Privacy Commissioner of Canada, and to notify affected individuals, where it is reasonable to believe the breach creates a real risk of significant harm. Both must happen as soon as feasible after the organization determines the breach occurred.
The organization must also notify any other organization or government institution that may be able to reduce the risk of harm, such as a bank or credit bureau.
PIPEDA also requires a record of every breach of security safeguards, whether or not it was reportable. Under the Breach of Security Safeguards Regulations, those records must be kept for 24 months and produced to the Commissioner on request.
Knowingly failing to report or to keep records is an offence under section 28 of PIPEDA, punishable by a fine of up to $100,000 on indictment.
Public bodies must notify affected individuals and the OIPC without unreasonable delay where a breach could reasonably be expected to result in significant harm. Private suppliers to public bodies should read their contracts closely, as these often require notice within hours, not days.
The test under PIPEDA has two parts, and the same framework is a sensible benchmark for voluntary decisions under PIPA.
Significant harm is defined in section 10.1(7) of PIPEDA to include bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property.
Real risk is assessed under section 10.1(8) by considering:
The assessment should be documented at the time it is made. A reasoned decision not to notify is defensible. An undocumented one rarely is.
A common error is treating encryption as conclusive. Encryption reduces risk only if the key was not also compromised and the encryption was actually applied to the affected data.
The order of operations matters. Decisions made in panic tend to destroy evidence, waive privilege or create statements that later appear in a statement of claim.
A ransom demand adds a separate layer of legal and practical risk. Paying does not remove any notification obligation, and it does not guarantee the data is destroyed.
For PIPEDA-regulated breaches, the Breach of Security Safeguards Regulations prescribe the content. A notice to individuals must include, among other things:
The notice must be conspicuous and given directly, with indirect notice permitted only in limited circumstances. Even where only PIPA applies, this list is a sound template.
Accuracy matters more than speed alone. A notice that understates the breach, or speaks too early about its scope, can become a liability if the facts change.
Regulatory consequences are usually the smaller part of the risk. Civil litigation, particularly class actions, drives most of the cost.
PIPA gives the BC Commissioner power to investigate complaints and, following an inquiry, to make binding orders. The Commissioner does not currently have power to impose administrative monetary penalties on private-sector organizations.
PIPA's offence provisions target specific misconduct, such as obstructing the Commissioner, disposing of information to evade an access request, or failing to comply with an order. An organization convicted of an offence can be fined up to $100,000.
Section 57 of PIPA gives an individual a cause of action for damages for actual harm suffered, but only after the Commissioner's order has become final or the organization has been convicted of an offence. That makes it a slower, narrower route than a civil claim.
The Privacy Act (BC) makes it a tort, actionable without proof of damage, for a person to wilfully and without a claim of right violate the privacy of another. Claims under that Act must be heard in the Supreme Court of British Columbia.
In 2024, the BC Court of Appeal held in G.D. v. South Coast British Columbia Transportation Authority, 2024 BCCA 252, and Campbell v. Capital One Financial Corporation, 2024 BCCA 253, that it is not plain and obvious a data custodian hacked by a third party cannot be liable under the Privacy Act. Reckless security practices may be enough to meet the "wilful" requirement.
That shift makes BC a more active forum for data breach class actions. Plaintiffs typically plead the Privacy Act alongside negligence, breach of contract and breach of confidence, and seek certification under the Class Proceedings Act (BC). Because the statutory tort is actionable without proof of loss, the absence of identity theft does not end the claim.
The ordinary two-year basic limitation period under the Limitation Act (BC) applies, running from discovery.
Where PIPEDA applies, a complainant who has received the Privacy Commissioner of Canada's report may apply to the Federal Court, which can order an organization to correct its practices and award damages, including damages for humiliation.
Directors of a BC company owe a statutory duty of care under section 142 of the Business Corporations Act (BC). Cyber risk is now a mainstream governance issue, and a board that has never reviewed an incident response plan is in a weaker position when a breach is examined after the fact.
On June 15, 2026, the federal government introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act and replace the privacy provisions of PIPEDA. The bill proposes a new federal regulator and a significantly stronger enforcement regime.
Bill C-36 is not law. Until it is enacted and in force, PIPEDA continues to govern. BC businesses subject to PIPEDA should monitor the bill, but should not change their breach-response procedures based on its current text.
BC's PIPA would not be replaced by Bill C-36. Provincially regulated businesses will remain under PIPA unless and until the BC Legislature amends it.
The organizations that manage breaches well have usually made the hard decisions in advance.
Not as a statutory requirement if only PIPA applies, because PIPA does not currently contain a mandatory breach-reporting section. Voluntary reporting is common and is generally advisable where there is a meaningful risk of harm. If PIPEDA applies, reporting to the Privacy Commissioner of Canada is mandatory where there is a real risk of significant harm.
Under PIPEDA, notification must be given as soon as feasible after the organization determines that a breach has occurred. There is no fixed number of hours. Contracts, insurance policies and public-sector agreements may impose shorter deadlines.
Potentially, yes. The Privacy Act (BC) tort is actionable without proof of damage, and the BC Court of Appeal has allowed claims against data custodians to proceed where reckless security practices are alleged. Whether a claim succeeds depends on the facts and the evidence.
It applies if you are a federally regulated business, or to the extent personal information crosses provincial or national borders in the course of commercial activity. Many BC businesses deal with both PIPA and PIPEDA for different data.
That is a business decision with legal consequences, and it should be made with counsel and your insurer. Payment does not discharge notification obligations, and there is no assurance the data will be deleted.
No. Bill C-36 was introduced on June 15, 2026 and has not been enacted. PIPEDA and PIPA continue to apply.
A data breach is a legal event as much as a technical one. In British Columbia, the absence of a mandatory reporting section in PIPA is not an absence of obligation. The security duty, the federal reporting regime, contractual promises and an increasingly active class action landscape all shape what you must do.
The decisions that matter most are made in the first few days. Organizations that have a plan, counsel and an insurer lined up before an incident tend to make better ones.
Speak with us to build a breach response plan, review your vendor contracts, or get immediate guidance if an incident is under way.
Informational Purposes Only
This article is intended for general informational purposes only and does not constitute legal advice. It does not create a solicitor-client relationship. Commercial leasing disputes are highly fact-specific, and the law may have changed since publication. You should consult a qualified BC commercial real estate lawyer before taking any steps to assign, sublet, or otherwise transfer your commercial lease.