Does a BC company have to report a breach?

Three different instruments get mixed together in this question, and they give three different answers. Which one binds you decides what you actually have to do.

The short version

  • Federally regulated or handling personal information in commercial activity across provincial lines — PIPEDA. There is a mandatory reporting duty where a breach creates a real risk of significant harm, plus a duty to keep records of breaches.
  • A BC private-sector organization or non-profit under BC PIPA. The Act requires reasonable security arrangements. It does not impose a mandatory breach-notification duty. Reporting to the Office of the Information and Privacy Commissioner is voluntary.
  • A BC public body under FIPPA. Mandatory notification to the affected individual and to the Commissioner, in force since 1 February 2023 under FIPPA s. 36.3, where the breach “could reasonably be expected to result in significant harm”, without unreasonable delay. It usually reaches suppliers through the contract schedule.
Which privacy Act imposes a breach-notification duty on you A decision starting from the question: who holds the personal information. Three branches. A BC private-sector organization falls under BC PIPA, which requires reasonable security and imposes no notification duty. A federal work or a cross-border transfer falls under PIPEDA, where notification is mandatory on the real-risk-of-significant-harm test. A BC public body falls under FIPPA section 36.3, where notification has been mandatory since 1 February 2023. Who holds the personal information? BC PRIVATE SECTOR BC PIPA Reasonable security. No notification duty. FEDERAL WORKS, CROSS-BORDER PIPEDA Mandatory, on RROSH. BC PUBLIC BODY FIPPA s.36.3 Mandatory since 1 February 2023.
The question decides the duty. Getting it wrong is what costs money.

The claim that is wrong

You will find pages asserting that BC PIPA was amended in 2023 to add mandatory breach notification, “bringing it in line with PIPEDA and the other provinces.” That is not supported by the statute. The OIPC's own material treats mandatory breach notification as a reform it has recommended — which is the opposite of it already being law.

It is worth being precise about where that claim comes from, because the half of it that is true is what makes it so durable. British Columbia did enact mandatory breach notification, and it did commence on 1 February 2023 — but in FIPPA s. 36.3, added by the Freedom of Information and Protection of Privacy Amendment Act, 2021, and it binds public bodies. PIPA, which is the Act that binds private-sector organizations and non-profits, was not amended and still contains no notification duty; it requires reasonable security arrangements and nothing more. So “BC”, “mandatory breach notification” and “2023” are each true, and the conclusion drawn from them is still wrong. The question that decides it is which Act you are under, which is the whole point of the list above.

This matters commercially, not just pedantically. If you buy a compliance programme sold to you on the basis of a BC notification deadline, you have bought against a duty that does not exist in that form. The real pressure on BC private-sector organizations is contractual: your customers, your insurer, and procurement.

What to do instead

Work out which instrument binds you, then work backwards from the document that is actually going to be read — the insurance application, the vendor questionnaire, the procurement schedule. Those have deadlines and consequences that are concrete today. Build the breach procedure because a breach is genuinely likely and because your contracts require it, not because of a BC statutory clock that has not been enacted.

Voluntary reporting to the OIPC still has a purpose: it is one of the ways an organization demonstrates that it took the matter seriously.

← All writing