Data Breach Obligations in BC: What to Do When It Happens

The first call usually comes on a Friday afternoon. A staff member clicked a link, a vendor's server was encrypted, or a customer list turned up somewhere it should not be. Within hours, someone has to decide who must be told, what can be said, and what must be preserved.

Those decisions are governed by your data breach obligations in BC, and they are more nuanced than most business owners expect. British Columbia's private-sector privacy statute does not contain an express breach-reporting section. Federal law does. Which one applies to you, and how you handle the first few days, shapes your regulatory exposure and your class action risk for years.

This guide explains which statute governs your business, when notification is mandatory or expected, how the "real risk of significant harm" test works, and what a defensible response looks like.

What Counts as a Data Breach Under BC Law?

In legal terms, a privacy breach is the loss of, unauthorized access to, or unauthorized collection, use, disclosure or disposal of personal information. Ransomware, phishing, a misdirected email and a lost laptop all qualify.

"Personal information" is defined broadly. Under the Personal Information Protection Act (BC) (PIPA), it means information about an identifiable individual, with carve-outs for business contact information and work product information.

Two practical points follow:

  • A breach does not require a hacker. An employee emailing a spreadsheet to the wrong client is a breach.
  • A breach does not require proof of misuse. The legal analysis begins when information is exposed, not when it is exploited.

Which Privacy Law Applies to Your Business in BC?

This is the first question to answer, because the notification rules differ sharply. Three statutes do most of the work.

PIPA: most private businesses and non-profits in BC

PIPA governs how private-sector organizations collect, use and disclose personal information within British Columbia, including employee personal information. It is overseen by the Office of the Information and Privacy Commissioner for British Columbia (OIPC).

If you are a BC retailer, professional firm, contractor, clinic, technology company or non-profit, PIPA is likely your primary statute.

PIPEDA: federal works and cross-border data

The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies in BC to federal works, undertakings and businesses, such as banks, telecommunications companies, airlines and interprovincial transport. It also applies to personal information that crosses provincial or national borders in the course of commercial activity.

Many BC businesses are subject to both regimes for different data flows. A Vancouver e-commerce company selling to customers across Canada should assume PIPEDA reaches at least part of its operations.

FIPPA: public bodies and their service providers

The Freedom of Information and Protection of Privacy Act (BC) (FIPPA) governs provincial public bodies: ministries, health authorities, municipalities, school districts and universities. Since February 1, 2023, FIPPA has required public bodies to notify affected individuals and the OIPC of privacy breaches that could reasonably be expected to cause significant harm.

This matters to private companies that serve the public sector. FIPPA requires a service provider's employees and associates who know of an unauthorized disclosure to report it to the public body immediately, and government contracts usually impose tighter reporting terms on top.

Is Data Breach Notification Mandatory in BC?

The answer depends entirely on which statute governs the data involved.

Under PIPA: no express duty, but not a free pass

PIPA does not currently contain a mandatory breach-notification provision. As of October 2026, no amendment adding one has been introduced, and the 2026 privacy amendments passed in BC changed FIPPA, not PIPA.

That does not make silence a safe default. Section 34 of PIPA requires an organization to protect personal information in its custody or under its control by making reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification or disposal. Where notice would help affected people protect themselves, a failure to give it can be difficult to reconcile with that duty.

The OIPC accepts voluntary breach reports and publishes guidance on containment, risk assessment and notification. In practice, a timely voluntary report usually positions a BC organization better than a complaint-driven investigation that begins months later.

Under PIPEDA: mandatory where there is a real risk of significant harm

Section 10.1 of PIPEDA requires an organization to report a breach of security safeguards to the Privacy Commissioner of Canada, and to notify affected individuals, where it is reasonable to believe the breach creates a real risk of significant harm. Both must happen as soon as feasible after the organization determines the breach occurred.

The organization must also notify any other organization or government institution that may be able to reduce the risk of harm, such as a bank or credit bureau.

PIPEDA also requires a record of every breach of security safeguards, whether or not it was reportable. Under the Breach of Security Safeguards Regulations, those records must be kept for 24 months and produced to the Commissioner on request.

Knowingly failing to report or to keep records is an offence under section 28 of PIPEDA, punishable by a fine of up to $100,000 on indictment.

Under FIPPA: mandatory for public bodies

Public bodies must notify affected individuals and the OIPC without unreasonable delay where a breach could reasonably be expected to result in significant harm. Private suppliers to public bodies should read their contracts closely, as these often require notice within hours, not days.

How Do You Assess a "Real Risk of Significant Harm"?

The test under PIPEDA has two parts, and the same framework is a sensible benchmark for voluntary decisions under PIPA.

Significant harm is defined in section 10.1(7) of PIPEDA to include bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property.

Real risk is assessed under section 10.1(8) by considering:

  • Sensitivity of the information. Financial account data, government identification numbers, health information and login credentials sit at the high end.
  • Probability of misuse. Who accessed it, whether it was encrypted, whether it was exfiltrated, and whether there is evidence of misuse.

The assessment should be documented at the time it is made. A reasoned decision not to notify is defensible. An undocumented one rarely is.

A common error is treating encryption as conclusive. Encryption reduces risk only if the key was not also compromised and the encryption was actually applied to the affected data.

What Should a BC Business Do in the First 72 Hours?

The order of operations matters. Decisions made in panic tend to destroy evidence, waive privilege or create statements that later appear in a statement of claim.

  1. Contain the breach. Isolate affected systems, reset credentials, and stop the flow of information. Do not wipe systems before forensic images are taken.
  2. Preserve evidence. Logs, access records, emails and the attacker's communications may all become evidence in regulatory or civil proceedings.
  3. Engage legal counsel early. Retaining forensic investigators through counsel can support a claim of privilege over their work, although privilege is never guaranteed and depends on the purpose of the engagement.
  4. Notify your insurer. Cyber policies typically have strict notice conditions and approved-vendor panels. Late notice can jeopardize coverage.
  5. Determine which statutes apply. Map the affected data to PIPA, PIPEDA, FIPPA, and any out-of-province laws affecting customers outside BC.
  6. Assess the risk of harm. Apply the real risk of significant harm framework and record the reasoning.
  7. Notify as required or advisable. Regulators, affected individuals, financial institutions, contractual counterparties and, where appropriate, law enforcement.
  8. Review your contracts. Customer, vendor and lender agreements often contain their own breach-notice clauses with short deadlines.

A ransom demand adds a separate layer of legal and practical risk. Paying does not remove any notification obligation, and it does not guarantee the data is destroyed.

What Must a Breach Notification Contain?

For PIPEDA-regulated breaches, the Breach of Security Safeguards Regulations prescribe the content. A notice to individuals must include, among other things:

  • A description of the circumstances of the breach
  • The day or period during which it occurred
  • The personal information involved
  • The steps the organization has taken to reduce the risk of harm
  • The steps individuals can take to protect themselves
  • Contact information for questions
  • Information about the organization's internal complaint process and the individual's right to complain to the Privacy Commissioner of Canada

The notice must be conspicuous and given directly, with indirect notice permitted only in limited circumstances. Even where only PIPA applies, this list is a sound template.

Accuracy matters more than speed alone. A notice that understates the breach, or speaks too early about its scope, can become a liability if the facts change.

What Is the Legal Exposure After a Data Breach in BC?

Regulatory consequences are usually the smaller part of the risk. Civil litigation, particularly class actions, drives most of the cost.

OIPC investigations and orders

PIPA gives the BC Commissioner power to investigate complaints and, following an inquiry, to make binding orders. The Commissioner does not currently have power to impose administrative monetary penalties on private-sector organizations.

PIPA's offence provisions target specific misconduct, such as obstructing the Commissioner, disposing of information to evade an access request, or failing to comply with an order. An organization convicted of an offence can be fined up to $100,000.

Damages under PIPA section 57

Section 57 of PIPA gives an individual a cause of action for damages for actual harm suffered, but only after the Commissioner's order has become final or the organization has been convicted of an offence. That makes it a slower, narrower route than a civil claim.

The Privacy Act (BC) and class actions

The Privacy Act (BC) makes it a tort, actionable without proof of damage, for a person to wilfully and without a claim of right violate the privacy of another. Claims under that Act must be heard in the Supreme Court of British Columbia.

In 2024, the BC Court of Appeal held in G.D. v. South Coast British Columbia Transportation Authority, 2024 BCCA 252, and Campbell v. Capital One Financial Corporation, 2024 BCCA 253, that it is not plain and obvious a data custodian hacked by a third party cannot be liable under the Privacy Act. Reckless security practices may be enough to meet the "wilful" requirement.

That shift makes BC a more active forum for data breach class actions. Plaintiffs typically plead the Privacy Act alongside negligence, breach of contract and breach of confidence, and seek certification under the Class Proceedings Act (BC). Because the statutory tort is actionable without proof of loss, the absence of identity theft does not end the claim.

The ordinary two-year basic limitation period under the Limitation Act (BC) applies, running from discovery.

Federal Court remedies under PIPEDA

Where PIPEDA applies, a complainant who has received the Privacy Commissioner of Canada's report may apply to the Federal Court, which can order an organization to correct its practices and award damages, including damages for humiliation.

Directors and governance

Directors of a BC company owe a statutory duty of care under section 142 of the Business Corporations Act (BC). Cyber risk is now a mainstream governance issue, and a board that has never reviewed an incident response plan is in a weaker position when a breach is examined after the fact.

How Could Federal Privacy Reform Change These Obligations?

On June 15, 2026, the federal government introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act and replace the privacy provisions of PIPEDA. The bill proposes a new federal regulator and a significantly stronger enforcement regime.

Bill C-36 is not law. Until it is enacted and in force, PIPEDA continues to govern. BC businesses subject to PIPEDA should monitor the bill, but should not change their breach-response procedures based on its current text.

BC's PIPA would not be replaced by Bill C-36. Provincially regulated businesses will remain under PIPA unless and until the BC Legislature amends it.

How Do You Prepare for a Breach Before It Happens?

The organizations that manage breaches well have usually made the hard decisions in advance.

  • Write an incident response plan that names decision-makers, outside counsel, forensic providers and the insurer's notice contact.
  • Map your data. Know what personal information you hold, where it sits, and which statute governs it.
  • Retain less. PIPA requires organizations to stop retaining personal information once it no longer serves a legal or business purpose. Data you no longer hold cannot be breached.
  • Review vendor contracts. Require prompt breach notice, cooperation, audit rights and appropriate indemnities from service providers holding your data.
  • Check your cyber insurance for notice conditions, panel requirements, sublimits and exclusions.
  • Keep a breach log, including minor incidents. Under PIPEDA it is mandatory; under PIPA it is evidence of reasonable security arrangements.
  • Run a tabletop exercise at least annually with management and, ideally, the board.

Frequently Asked Questions

Do I have to report a data breach to the OIPC in BC?

Not as a statutory requirement if only PIPA applies, because PIPA does not currently contain a mandatory breach-reporting section. Voluntary reporting is common and is generally advisable where there is a meaningful risk of harm. If PIPEDA applies, reporting to the Privacy Commissioner of Canada is mandatory where there is a real risk of significant harm.

How quickly must I notify affected individuals?

Under PIPEDA, notification must be given as soon as feasible after the organization determines that a breach has occurred. There is no fixed number of hours. Contracts, insurance policies and public-sector agreements may impose shorter deadlines.

Can affected customers sue us if no one's identity was stolen?

Potentially, yes. The Privacy Act (BC) tort is actionable without proof of damage, and the BC Court of Appeal has allowed claims against data custodians to proceed where reckless security practices are alleged. Whether a claim succeeds depends on the facts and the evidence.

Does PIPEDA apply to my BC business?

It applies if you are a federally regulated business, or to the extent personal information crosses provincial or national borders in the course of commercial activity. Many BC businesses deal with both PIPA and PIPEDA for different data.

Should we pay a ransom?

That is a business decision with legal consequences, and it should be made with counsel and your insurer. Payment does not discharge notification obligations, and there is no assurance the data will be deleted.

Does Bill C-36 change our obligations now?

No. Bill C-36 was introduced on June 15, 2026 and has not been enacted. PIPEDA and PIPA continue to apply.

The Bottom Line on Data Breach Obligations in BC

A data breach is a legal event as much as a technical one. In British Columbia, the absence of a mandatory reporting section in PIPA is not an absence of obligation. The security duty, the federal reporting regime, contractual promises and an increasingly active class action landscape all shape what you must do.

The decisions that matter most are made in the first few days. Organizations that have a plan, counsel and an insurer lined up before an incident tend to make better ones.

Speak with us to build a breach response plan, review your vendor contracts, or get immediate guidance if an incident is under way.

Informational Purposes Only

This article is intended for general informational purposes only and does not constitute legal advice. It does not create a solicitor-client relationship. Commercial leasing disputes are highly fact-specific, and the law may have changed since publication. You should consult a qualified BC commercial real estate lawyer before taking any steps to assign, sublet, or otherwise transfer your commercial lease.

‍

‍

By
Kiyan Seyedi
Founder, Fulcrum Law
•
15 min read