
If your business operates a website and collects any personal information — names, email addresses, IP addresses, or payment details — British Columbia law likely requires a compliant privacy policy. The website privacy policy requirements BC businesses must follow come primarily from the Personal Information Protection Act (PIPA), British Columbia's private-sector privacy statute, not from a single generic "Canadian privacy law." Many owners assume a downloaded template satisfies their obligations. It usually does not. This guide explains which law applies to your website, what a compliant policy must contain, the mandatory breach notification rules in force since 2023, and the practical consequences of non-compliance.
In most cases, yes. PIPA applies to "organizations" — a broad category that includes corporations, sole proprietorships, partnerships, and unincorporated associations — that collect, use, or disclose personal information in the course of commercial activity in British Columbia. A website that operates a contact form, e-commerce checkout, email newsletter sign-up, or analytics tracking is collecting personal information, which engages PIPA regardless of the business's size.
Section 5 of PIPA imposes a general duty on organizations to develop and follow reasonable policies and practices to meet their obligations under the Act, and to make information about those policies available on request. In practice, this is the statutory basis for requiring a documented, publicly accessible privacy policy on a commercial website — it is not merely good practice, it is a legal obligation for most operating businesses.
A common point of confusion for BC business owners is whether the applicable law is the federal Personal Information Protection and Electronic Documents Act (PIPEDA) or the provincial PIPA. The two statutes are not interchangeable, and the distinction matters for compliance.
For most BC-based businesses selling primarily to BC or Canadian customers through a standard commercial website, PIPA is the operative statute. Businesses with interprovincial operations, federally regulated status, or significant out-of-country data processing should have counsel confirm which framework — or combination of frameworks — applies.
PIPA does not simply require "consent" in the abstract. It applies a structured test to each stage of handling personal information, and a privacy policy should reflect all three stages accurately.
This "reasonable person" standard is the analytical core of PIPA. It means a business cannot rely on broad, catch-all consent language to justify collecting more data than the stated purpose requires, and it means the same standard is applied by the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) when it evaluates a complaint.
A privacy policy that merely states "we value your privacy" does not meet PIPA's requirements. To satisfy the Act, and to withstand scrutiny from the OIPC BC, a website privacy policy should address:
Since February 1, 2023, PIPA has included mandatory breach notification obligations, added by the Personal Information Protection Amendment Act, 2021. These provisions require an organization to notify both the OIPC BC and affected individuals where a privacy breach creates a real risk of significant harm to an individual, and to do so without unreasonable delay.
PIPA also requires organizations to keep records of all privacy breaches involving personal information in their custody or control — including breaches that do not meet the notification threshold. This record-keeping obligation exists independently of whether notification was required, and the OIPC BC may request those records as part of an investigation or audit.
Whether a given incident creates a "real risk of significant harm" is a fact-specific assessment that considers the sensitivity of the information involved and the probability it will be misused. Businesses should have a breach response protocol in place before an incident occurs, not drafted for the first time under pressure.
IP addresses, device identifiers, and browsing data collected through cookies or analytics tools can constitute personal information under PIPA where that data, alone or combined with other information, could identify an individual. This means tools such as website analytics platforms and advertising pixels are not exempt from PIPA simply because they operate passively in the background.
A compliant privacy policy should disclose the use of such tools, and businesses should implement a genuine consent mechanism — commonly a cookie banner with meaningful choices — rather than a banner that merely acknowledges tracking is occurring.
Where a website's data is processed or stored by a vendor located outside British Columbia or Canada, PIPA does not prohibit this, but the reasonable-person standard supports disclosing the storage location and the fact that foreign law may permit government access to that data. This is best practice for private organizations and is close to a hard requirement for public bodies under FIPPA.
Businesses running email marketing campaigns from their website should also note that Canada's Anti-Spam Legislation (CASL), a federal statute, separately governs consent requirements for sending commercial electronic messages. CASL compliance and PIPA-compliant privacy disclosures are related but distinct obligations, and a business needs both.
The OIPC BC has authority to receive and investigate complaints regarding an organization's compliance with PIPA, and can issue orders requiring an organization to correct its practices. A decision or order of the Commissioner may be subject to judicial review by the Supreme Court of British Columbia under the Judicial Review Procedure Act.
PIPA also contains offence provisions. Contravening certain obligations under the Act — including breach notification requirements — can result in prosecution and, on conviction, a fine. These penalties are pursued through the offence process rather than imposed directly by the Commissioner as an administrative penalty, which is a meaningful procedural distinction from privacy regimes in some other jurisdictions.
Beyond statutory penalties, non-compliance carries commercial risk: loss of customer trust, difficulty passing vendor or investor due diligence, and potential breach of contractual privacy warranties given to business partners, payment processors, or platform providers.
Yes. PIPA does not include a general exemption for small organizations. It applies based on the nature of the activity — collecting personal information in the course of commercial activity in BC — rather than the size of the business.
No. A Terms of Service agreement governs the contractual terms of using a website or service. A Privacy Policy specifically addresses the collection, use, and disclosure of personal information under PIPA. Most commercial websites need both, and they serve different legal functions.
Generally, yes, where the data collected could identify an individual. Best practice is to disclose the tool in your privacy policy and use a consent mechanism that gives visitors a genuine choice rather than a purely informational notice.
PIPA does not provide an exhaustive definition. The assessment considers the sensitivity of the information involved and the probability it will be misused. Because this is a fact-specific judgment call, businesses facing a suspected breach should seek legal advice promptly rather than assume no notification is required.
The Commissioner's order-making power under PIPA is separate from the Act's offence provisions. Monetary penalties arise through prosecution of an offence, not as an administrative penalty imposed directly by the Commissioner.
It can. Interprovincial sales and data flows may engage PIPEDA concurrently with PIPA, depending on how the transaction and data transfer occur. Businesses operating beyond BC should have their compliance framework reviewed to confirm which statute, or combination of statutes, applies.
Informational Purposes Only
This article is intended for general informational purposes only and does not constitute legal advice. It does not create a solicitor-client relationship. Commercial leasing disputes are highly fact-specific, and the law may have changed since publication. You should consult a qualified BC commercial real estate lawyer before taking any steps to assign, sublet, or otherwise transfer your commercial lease.