Law / Canada / British Columbia

Personal Information Protection Act, comprehensive regime

Also known as PIPA.

Personal Information Protection Act, S.B.C. 2003, c. 63

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived . Publisher's page: https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01

In force since .

A comprehensive regime rule binding private bodies.

Enforcement body
Information and Privacy Commissioner for British Columbia
Obligation class
Consent, Disclosure, Data subject rights, Governance, Security, Retention

As of .

What it requires

  • Do not collect, use or disclose personal information about an individual without the individual's consent, unless the Act authorizes it without consent or deems the consent given. Consent obtained by false or misleading information, or by deceptive or misleading practices, is not validly given.
  • Do not require an individual to consent to the collection, use or disclosure of personal information beyond what is necessary to provide a product or service, as a condition of supplying it.
  • On or before collecting personal information from an individual, disclose the purposes of the collection verbally or in writing and, on request, the position name or title and contact information of an officer or employee who can answer the individual's questions. This does not apply to a collection covered by implicit consent under section 8 (1) or (2).
  • Collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances and that fulfil the purposes you disclosed or are otherwise permitted by the Act.
  • Personal information available to the public may be collected, used or disclosed without consent on that basis only from a source the Regulations prescribe: a telephone directory or directory assistance service, a professional or business directory, a registry to which the public has a right of access, or a printed or electronic publication that is available to the public, on the conditions the Regulations state.
  • Do not collect, use or disclose personal information from a publication where a court has prohibited its publication or the commissioner has ordered that the information was published contrary to the Act.
  • Designate one or more individuals to be responsible for ensuring that you comply with the Act, and make their position names or titles and contact information available to the public. You remain responsible for personal information under your control, including information not in your custody.
  • Develop and follow the policies and practices you need to meet the Act, develop a process for responding to complaints, and make information about both available on request.
  • On an individual's written request, give them their personal information under your control, the ways it has been and is being used, and the names of the individuals and organizations it has been disclosed to, subject to the exceptions and prohibitions in section 23.
  • Correct an error or omission in an individual's personal information when satisfied on reasonable grounds that a correction request should be implemented, send the corrected information to each organization it was disclosed to during the previous year, and annotate the information with the correction requested when you make none.
  • On reasonable notice, allow an individual to withdraw consent at any time, tell them the likely consequences of withdrawing, and then stop collecting, using and disclosing the information unless the Act permits it without consent. An individual may not withdraw consent where doing so would frustrate the performance of a legal obligation.
  • Protect personal information in your custody or under your control by making reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks.
  • Keep personal information you used to make a decision that directly affects an individual for at least one year after using it, so that the individual has a reasonable opportunity to obtain access to it.
  • Destroy documents containing personal information, or remove the means by which it can be associated with particular individuals, as soon as it is reasonable to assume that the purpose of collection is no longer served and retention is no longer necessary for legal or business purposes.
  • Comply with an order of the commissioner not later than 30 days after being given a copy, unless an application for judicial review is brought before that period ends.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Section 56 makes it an offence to use deception or coercion to collect personal information in contravention of the Act, to dispose of personal information with intent to evade an access request, to obstruct the commissioner, to make a false statement to or mislead the commissioner, to contravene the employee-protection section, or to fail to comply with a commissioner's order, and section 56(2) sets a fine for each.

Penalty structure

Section 56(2) sets the fine for an offence under section 56(1) at not more than $100,000 for a person other than an individual and not more than $10,000 for an individual.

Rule
Fixed only
As of
Currency
CAD
Fixed cap
100,000

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Act applies to every organization, which it defines to include a person, an unincorporated association, a trade union, a trust or a not for profit organization, and defines not to include a public body. An organization must not collect, use or disclose personal information about an individual unless the individual consents, the Act authorizes the collection, use or disclosure without consent, or the Act deems it to be consented to by the individual.

Each collection, use or disclosure must also be for purposes that a reasonable person would consider appropriate in the circumstances. One exception to the consent rule covers personal information that is available to the public from a source prescribed for that purpose.

The Personal Information Protection Act Regulations prescribe four such sources: a telephone directory or directory assistance service, a professional or business directory, a registry to which the public has a right of access, and a printed or electronic publication that is available to the public, including a magazine, book or newspaper.

The directory sources apply only where the individual is permitted to refuse to be included, and the registry source applies only where the information is collected under the authority of an enactment, the laws of Canada or a province, or a municipal bylaw. The Regulations withdraw the publication source where a court has prohibited the publication of the personal information or the commissioner has ordered that it was published contrary to the Act.

The Act does not apply to collection, use or disclosure for an individual's personal or domestic purposes and no other purpose, for journalistic, artistic or literary purposes and no other purpose, or where the federal Personal Information Protection and Electronic Documents Act applies to it.

On request, an organization must give an individual their personal information under its control, the ways it has been and is being used, and the names of the individuals and organizations to whom it has been disclosed, subject to the exceptions in section 23. An organization must protect personal information in its custody or under its control by making reasonable security arrangements.

An organization must destroy documents containing personal information, or remove the means by which it can be associated with particular individuals, as soon as it is reasonable to assume that the purpose of collection is no longer served and retention is no longer necessary for legal or business purposes. Using deception or coercion to collect personal information in contravention of the Act, and failing to comply with an order of the commissioner, are among the offences the Act creates.

An individual who commits an offence is liable to a fine of not more than $10,000, and a person other than an individual to a fine of not more than $100,000. An individual affected by a commissioner's order that has become final has a cause of action against the organization for damages for actual harm suffered as a result of its breach of the Act.

A person affected by the conduct behind an offence of which an organization has been convicted, where the conviction has become final, has a cause of action against the organization for damages for actual harm.

When LexLint raises it

When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot, sends automated outreach, makes high-risk automated decisions, processes voice recordings, processes biometric data, operates a social platform, serves under-18s, operates an app store, ships a mobile app or reuses other publishers' content.

Back to the example  ·  Lint your app