Meaningful consent under PIPEDA and BC PIPA

Consent is meaningful only if it is reasonable to expect that the people you are addressing would understand the nature, purpose and consequences of what they agreed to. That is the test in section 6.1 of PIPEDA, and BC’s Personal Information Protection Act reaches a similar place by a different route. A checkbox proves a click, not understanding.

What do the regulators expect?

The federal commissioner and the Alberta and BC commissioners issued the Guidelines for obtaining meaningful consent jointly, and they remain the published guidance as of September 2026. They set out seven principles:

  1. Emphasize key elements: what is collected, who it is shared with, for what purposes, and the risk of harm.
  2. Let people control the level of detail and when they get it, typically by layering.
  3. Give clear yes-or-no options for anything not necessary to provide the service.
  4. Be innovative and creative: just-in-time, in context, not a paper policy pasted onto a screen.
  5. Consider the consumer’s perspective, and test that the audience actually understands.
  6. Make consent dynamic and ongoing, not a single moment at sign-up.
  7. Be accountable: stand ready to show the process works.

The seventh is the one we see overlooked most often. Is a privacy policy enough? No. The regulators’ own guidelines say that pointing to a line buried in a privacy policy will not suffice to show valid consent. The key elements have to be in front of the person at the moment they decide.

When is implied consent enough?

PIPEDA’s Schedule 1 says an organization should generally seek express consent when the information is likely to be considered sensitive, and that implied consent is generally appropriate when it is less sensitive. The guidelines sharpen that into three triggers. So when is express consent needed? Generally when the information is sensitive, when the use falls outside what the person would reasonably expect, or when it creates a meaningful residual risk of significant harm. Any one of the three is enough to move you to express consent.

Sensitivity is contextual. Health and financial data almost always qualify, but so can an ordinary mailing list if it reveals something about the people on it.

How does BC PIPA differ?

QuestionPIPEDABC PIPA
When is consent valid?Only if it is reasonable to expect that the individuals the activity is directed at would understand its nature, purpose and consequences (s. 6.1)When the purposes were disclosed on or before collection and nothing false or deceptive was used (ss. 7, 10)
Consent without asking?Implied consent, for less sensitive informationDeemed consent for an obvious purpose (s. 8(1))
Opt-out?Depends on sensitivity and expectationsAllowed by notice with a reasonable chance to decline, if reasonable given sensitivity (s. 8(3))
Bundling?Prohibited beyond what the explicitly specified, legitimate purposes require (Sch. 1, 4.3.3)Prohibited beyond what is necessary to provide the product or service (s. 7(2))

What is deemed consent? BC PIPA deems consent where the purpose would be obvious to a reasonable person and the individual voluntarily provides the information for that purpose. It covers that purpose only, and it does not stretch to a new one later. The common myth is that deemed consent is a general licence to use whatever a customer hands over. It is narrow, and section 8(4) closes the door on repurposing.

Both Acts let individuals withdraw consent on reasonable notice, and both require the organization to tell them what withdrawing means for them (PIPEDA Schedule 1 clause 4.3.8; BC PIPA s. 9(2)). PIPEDA allows legal or contractual restrictions on withdrawal. BC allows only narrow ones: where withdrawal would frustrate the performance of a legal obligation, and certain consents given to a credit reporting agency (s. 9(5)-(6)). Design the withdrawal path at the same time as the consent path.

Can consent be a condition of service?

Can you make consent a condition of using the service? Only for what the service actually needs. BC PIPA s. 7(2) bars requiring consent beyond what is necessary to provide the product or service. PIPEDA Schedule 1 clause 4.3.3 bars requiring it beyond what the explicitly specified, legitimate purposes require. The regulators’ guidelines treat anything beyond that as a separate choice the person must be given. Analytics, marketing, model training and sharing with partners for their own purposes are the usual places a bundle hides. If you cannot explain in one sentence why the service cannot work without it, it is a separate choice.

What should you fix first in a consent flow?

  • List every purpose you use personal information for, and mark each as integral or optional.
  • Put the four key elements up front at the point of decision, with the full policy one layer down.
  • Move sensitive or unexpected uses to express, opt-in consent.
  • Keep a record of what each person saw and chose, and when, so you can show the process works.

Which Act applies to you depends on where and how you operate; the map is in Canadian privacy law map. Whether a specific practice is lawful is a question for your counsel, and we work alongside them. The program work is Canadian privacy readiness, and new uses are best tested in a privacy impact assessment.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Is a privacy policy enough to get consent?

No. The regulators’ own guidelines say that pointing to a line buried in a privacy policy will not suffice to show valid consent. The key elements have to be in front of the person at the moment they decide.

When do we need express rather than implied consent?

Generally when the information is sensitive, when the use falls outside what the person would reasonably expect, or when it creates a meaningful residual risk of significant harm. Any one of the three is enough to move you to express consent.

What is deemed consent under BC PIPA?

BC PIPA deems consent where the purpose would be obvious to a reasonable person and the individual voluntarily provides the information for that purpose. It covers that purpose only, and it does not stretch to a new one later.

Can we make consent a condition of using the service?

Only for what the service actually needs. BC PIPA s. 7(2) bars requiring consent beyond what is necessary to provide the product or service. PIPEDA Schedule 1 clause 4.3.3 bars requiring it beyond what the explicitly specified, legitimate purposes require. The regulators’ guidelines treat anything beyond that as a separate choice the person must be given.

Check your consent flow

Send us the sign-up screen and the privacy notice behind it. The reply says where the key elements are missing and which uses look like candidates for their own choice, for your counsel to confirm. More of our writing is indexed at writing.

Discuss a scope