Law / Canada / British Columbia

British Columbia

All 1 named instruments researched to a stage, across one of the seven areas of law we track: 1 in force. As of .

  1. AI law
  2. Privacy law 1
  3. Scraping law not researched
  4. Cybersecurity law not researched
  5. Communications law not researched
  6. Age gating law not researched
  7. Reuse law not researched

in forcenot yet in forceblocked by a courtproposedno longer in force

Case law

  • No current case law for British Columbia AI law
  • No current case law for British Columbia privacy law
  • No current case law for British Columbia scraping law
  • No current case law for British Columbia cybersecurity law
  • No current case law for British Columbia communications law
  • No current case law for British Columbia age gating law
  • No current case law for British Columbia reuse law

Privacy law1 instrument, 1 in force

Research summary (158 words)

British Columbia's private-sector personal-information regime is the Personal Information Protection Act (chapter 63 of the Statutes of British Columbia, 2003), which applies to every organization other than a public body and is administered by the commissioner. The Act does not apply to collection, use or disclosure to which the federal Personal Information Protection and Electronic Documents Act applies.

It rests on consent and on purposes a reasonable person would consider appropriate, allows personal information available to the public to be collected, used and disclosed without consent from the four kinds of source the Regulations prescribe, and gives individuals rights of access and correction.

The Act sets out no duty to notify a person or the commissioner of a security breach, no restriction on transferring personal information outside British Columbia or Canada, no automated-decision right and no biometric or other special category of personal information, although the sensitivity of the information bears on implicit consent by notice and opt-out.

Comprehensive regime

Personal Information Protection Act, comprehensive regime

Personal Information Protection Act, S.B.C. 2003, c. 63Consolidated text of the Personal Information Protection Act, King's Printer for British Columbia (BC Laws)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived . Publisher's page: https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01

In force since . Binds private bodies.

What this law does

The Act applies to every organization, which it defines to include a person, an unincorporated association, a trade union, a trust or a not for profit organization, and defines not to include a public body. An organization must not collect, use or disclose personal information about an individual unless the individual consents, the Act authorizes the collection, use or disclosure without consent, or the Act deems it to be consented to by the individual.

Each collection, use or disclosure must also be for purposes that a reasonable person would consider appropriate in the circumstances. One exception to the consent rule covers personal information that is available to the public from a source prescribed for that purpose.

The Personal Information Protection Act Regulations prescribe four such sources: a telephone directory or directory assistance service, a professional or business directory, a registry to which the public has a right of access, and a printed or electronic publication that is available to the public, including a magazine, book or newspaper.

The directory sources apply only where the individual is permitted to refuse to be included, and the registry source applies only where the information is collected under the authority of an enactment, the laws of Canada or a province, or a municipal bylaw. The Regulations withdraw the publication source where a court has prohibited the publication of the personal information or the commissioner has ordered that it was published contrary to the Act.

The Act does not apply to collection, use or disclosure for an individual's personal or domestic purposes and no other purpose, for journalistic, artistic or literary purposes and no other purpose, or where the federal Personal Information Protection and Electronic Documents Act applies to it.

On request, an organization must give an individual their personal information under its control, the ways it has been and is being used, and the names of the individuals and organizations to whom it has been disclosed, subject to the exceptions in section 23. An organization must protect personal information in its custody or under its control by making reasonable security arrangements.

An organization must destroy documents containing personal information, or remove the means by which it can be associated with particular individuals, as soon as it is reasonable to assume that the purpose of collection is no longer served and retention is no longer necessary for legal or business purposes. Using deception or coercion to collect personal information in contravention of the Act, and failing to comply with an order of the commissioner, are among the offences the Act creates.

An individual who commits an offence is liable to a fine of not more than $10,000, and a person other than an individual to a fine of not more than $100,000. An individual affected by a commissioner's order that has become final has a cause of action against the organization for damages for actual harm suffered as a result of its breach of the Act.

A person affected by the conduct behind an offence of which an organization has been convicted, where the conviction has become final, has a cause of action against the organization for damages for actual harm.

What it requires

Where nothing was found1 area of law

These areas of law were researched here and no instrument was recorded. Each finding says what the research checked, as of the date under it. It describes our search, not a guarantee that no such law exists.

AI law

In Moffatt v. Air Canada, 2024 BCCRT 149, the British Columbia Civil Resolution Tribunal held that a company is responsible for all the information on its website, whether it comes from a static page or a chatbot, and that failing to take reasonable care to ensure a chatbot was accurate supported a claim of negligent misrepresentation. The decision is a small claims ruling applying the tort of negligent misrepresentation. The province's statutes and regulations that bear on AI systems are not described here.

As of .

Reporting clocks that run here1 instrument

The instruments whose obligation lines set a deadline for reporting an incident, a vulnerability or a personal-data breach, each deadline read from the sentence that carries it and listed shortest first. The law of British Columbia comes first, then the law of the bodies above it that applies here.

The law of Canada, which applies in British Columbia

as soon as feasible

PIPEDA breach of security safeguards regime

S.C. 2000, c. 5, ss. 10.1-10.3privacy law, in force since

The sentence the clocks are read from

Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.

Which of these one incident starts turns on the facts: the incident method works that through. The clocks document draws every clock in the corpus on one axis, with the sentence beside every rung.

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.