Website Privacy Policy Requirements for BC Businesses: A Legal Guide for Owners

If your business operates a website and collects any personal information — names, email addresses, IP addresses, or payment details — British Columbia law likely requires a compliant privacy policy. The website privacy policy requirements BC businesses must follow come primarily from the Personal Information Protection Act (PIPA), British Columbia's private-sector privacy statute, not from a single generic "Canadian privacy law." Many owners assume a downloaded template satisfies their obligations. It usually does not. This guide explains which law applies to your website, what a compliant policy must contain, the mandatory breach notification rules in force since 2023, and the practical consequences of non-compliance.

Do BC Businesses Need a Website Privacy Policy?

In most cases, yes. PIPA applies to "organizations" — a broad category that includes corporations, sole proprietorships, partnerships, and unincorporated associations — that collect, use, or disclose personal information in the course of commercial activity in British Columbia. A website that operates a contact form, e-commerce checkout, email newsletter sign-up, or analytics tracking is collecting personal information, which engages PIPA regardless of the business's size.

Section 5 of PIPA imposes a general duty on organizations to develop and follow reasonable policies and practices to meet their obligations under the Act, and to make information about those policies available on request. In practice, this is the statutory basis for requiring a documented, publicly accessible privacy policy on a commercial website — it is not merely good practice, it is a legal obligation for most operating businesses.

PIPA or PIPEDA? Determining Which Law Applies to Your Website

A common point of confusion for BC business owners is whether the applicable law is the federal Personal Information Protection and Electronic Documents Act (PIPEDA) or the provincial PIPA. The two statutes are not interchangeable, and the distinction matters for compliance.

  • PIPA governs private-sector organizations operating in BC for commercial activity conducted within the province. Because PIPA has been declared "substantially similar" to PIPEDA under the federal exemption order for British Columbia, PIPEDA generally does not apply to the purely intra-provincial collection, use, and disclosure of personal information by organizations already subject to PIPA.
  • PIPEDA continues to apply to organizations that are federal works, undertakings, or businesses — banks, airlines, telecommunications carriers, and interprovincial transportation providers — even if they are headquartered or operate in BC.
  • PIPEDA can also be engaged where personal information is disclosed for consideration across provincial or national borders, which is relevant for BC businesses selling to customers in other provinces or using out-of-province service providers.
  • The Freedom of Information and Protection of Privacy Act (FIPPA) is a separate statute that governs public bodies — municipalities, health authorities, school boards, and Crown corporations — not private businesses. A BC business contracting with a public body may need to align its privacy practices with FIPPA obligations imposed through that contract, but FIPPA itself does not directly regulate a private company's website.

For most BC-based businesses selling primarily to BC or Canadian customers through a standard commercial website, PIPA is the operative statute. Businesses with interprovincial operations, federally regulated status, or significant out-of-country data processing should have counsel confirm which framework — or combination of frameworks — applies.

The Legal Test: Collecting, Using, and Disclosing Personal Information Under PIPA

PIPA does not simply require "consent" in the abstract. It applies a structured test to each stage of handling personal information, and a privacy policy should reflect all three stages accurately.

  • Purpose identification: before or at the time personal information is collected, the organization must identify the purpose for collection, in accordance with PIPA's notification requirements.
  • Consent: collection, use, and disclosure generally require the individual's consent — express or deemed. Deemed consent may apply where an individual voluntarily provides information for an obvious purpose. Consent may be withdrawn on reasonable notice, subject to legal or contractual restrictions.
  • Reasonableness limit: even with consent, PIPA restricts an organization to collecting, using, and disclosing personal information only to the extent a reasonable person would consider appropriate in the circumstances, and only to the extent necessary to fulfill the identified purpose.

This "reasonable person" standard is the analytical core of PIPA. It means a business cannot rely on broad, catch-all consent language to justify collecting more data than the stated purpose requires, and it means the same standard is applied by the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) when it evaluates a complaint.

What a Legally Sound Website Privacy Policy Must Include

A privacy policy that merely states "we value your privacy" does not meet PIPA's requirements. To satisfy the Act, and to withstand scrutiny from the OIPC BC, a website privacy policy should address:

  • The identity and contact information of the organization, and of the individual or officer designated to receive privacy-related complaints and requests.
  • The specific purposes for which personal information is collected (for example: order fulfillment, account creation, marketing communications, or website analytics).
  • The categories of personal information collected, including information gathered passively through cookies, tracking pixels, and analytics tools.
  • How and when consent is obtained, and how an individual may withdraw consent.
  • Whether personal information is disclosed to third-party service providers (payment processors, cloud hosting, email marketing platforms), and whether any of those providers store or process data outside British Columbia.
  • Retention periods and destruction or de-identification practices for personal information no longer required for the identified purpose.
  • An individual's right to request access to, and correction of, their own personal information, consistent with PIPA's access and correction provisions.
  • The process for submitting a complaint internally, and notice that a complaint may also be directed to the OIPC BC.

Mandatory Breach Notification Requirements Under PIPA

Since February 1, 2023, PIPA has included mandatory breach notification obligations, added by the Personal Information Protection Amendment Act, 2021. These provisions require an organization to notify both the OIPC BC and affected individuals where a privacy breach creates a real risk of significant harm to an individual, and to do so without unreasonable delay.

PIPA also requires organizations to keep records of all privacy breaches involving personal information in their custody or control — including breaches that do not meet the notification threshold. This record-keeping obligation exists independently of whether notification was required, and the OIPC BC may request those records as part of an investigation or audit.

Whether a given incident creates a "real risk of significant harm" is a fact-specific assessment that considers the sensitivity of the information involved and the probability it will be misused. Businesses should have a breach response protocol in place before an incident occurs, not drafted for the first time under pressure.

Cookies, Website Analytics, and Cross-Border Data Transfers

IP addresses, device identifiers, and browsing data collected through cookies or analytics tools can constitute personal information under PIPA where that data, alone or combined with other information, could identify an individual. This means tools such as website analytics platforms and advertising pixels are not exempt from PIPA simply because they operate passively in the background.

A compliant privacy policy should disclose the use of such tools, and businesses should implement a genuine consent mechanism — commonly a cookie banner with meaningful choices — rather than a banner that merely acknowledges tracking is occurring.

Where a website's data is processed or stored by a vendor located outside British Columbia or Canada, PIPA does not prohibit this, but the reasonable-person standard supports disclosing the storage location and the fact that foreign law may permit government access to that data. This is best practice for private organizations and is close to a hard requirement for public bodies under FIPPA.

Businesses running email marketing campaigns from their website should also note that Canada's Anti-Spam Legislation (CASL), a federal statute, separately governs consent requirements for sending commercial electronic messages. CASL compliance and PIPA-compliant privacy disclosures are related but distinct obligations, and a business needs both.

Enforcement, Complaints, and Penalties for Non-Compliance

The OIPC BC has authority to receive and investigate complaints regarding an organization's compliance with PIPA, and can issue orders requiring an organization to correct its practices. A decision or order of the Commissioner may be subject to judicial review by the Supreme Court of British Columbia under the Judicial Review Procedure Act.

PIPA also contains offence provisions. Contravening certain obligations under the Act — including breach notification requirements — can result in prosecution and, on conviction, a fine. These penalties are pursued through the offence process rather than imposed directly by the Commissioner as an administrative penalty, which is a meaningful procedural distinction from privacy regimes in some other jurisdictions.

Beyond statutory penalties, non-compliance carries commercial risk: loss of customer trust, difficulty passing vendor or investor due diligence, and potential breach of contractual privacy warranties given to business partners, payment processors, or platform providers.

Practical Steps to Build a Compliant Privacy Policy

  • Audit every point on your website where personal information is collected — forms, checkout, chat widgets, cookies, and third-party embeds.
  • Designate a privacy officer or contact responsible for PIPA compliance, even in a small organization.
  • Draft a privacy policy that reflects your actual data practices, not a generic template — inaccurate disclosures create their own liability.
  • Implement a real consent mechanism for cookies and marketing communications, not a banner that only informs.
  • Put a breach response plan in place before an incident occurs, including a process for assessing "real risk of significant harm."
  • Review data processing and hosting agreements with vendors to confirm where personal information is stored and how it is protected.
  • Schedule a periodic legal review of your privacy policy as your business's data practices evolve.

Frequently Asked Questions

Does PIPA apply to a small business with only a few employees?

Yes. PIPA does not include a general exemption for small organizations. It applies based on the nature of the activity — collecting personal information in the course of commercial activity in BC — rather than the size of the business.

Is a Terms of Service the same as a Privacy Policy?

No. A Terms of Service agreement governs the contractual terms of using a website or service. A Privacy Policy specifically addresses the collection, use, and disclosure of personal information under PIPA. Most commercial websites need both, and they serve different legal functions.

Do I need consent for Google Analytics or similar tracking cookies?

Generally, yes, where the data collected could identify an individual. Best practice is to disclose the tool in your privacy policy and use a consent mechanism that gives visitors a genuine choice rather than a purely informational notice.

What counts as a "real risk of significant harm" for breach notification?

PIPA does not provide an exhaustive definition. The assessment considers the sensitivity of the information involved and the probability it will be misused. Because this is a fact-specific judgment call, businesses facing a suspected breach should seek legal advice promptly rather than assume no notification is required.

Can the OIPC BC fine my business directly?

The Commissioner's order-making power under PIPA is separate from the Act's offence provisions. Monetary penalties arise through prosecution of an offence, not as an administrative penalty imposed directly by the Commissioner.

Does PIPEDA apply if my BC business sells to customers across Canada?

It can. Interprovincial sales and data flows may engage PIPEDA concurrently with PIPA, depending on how the transaction and data transfer occur. Businesses operating beyond BC should have their compliance framework reviewed to confirm which statute, or combination of statutes, applies.

Informational Purposes Only

This article is intended for general informational purposes only and does not constitute legal advice. It does not create a solicitor-client relationship. Commercial leasing disputes are highly fact-specific, and the law may have changed since publication. You should consult a qualified BC commercial real estate lawyer before taking any steps to assign, sublet, or otherwise transfer your commercial lease.

By
Kiyan Seyedi
Founder, Fulcrum Law
15 min read