What BC's Personal Information Protection Act means for your business IT, in plain English, with a practical checklist of security safeguards.

If your business collects information about customers, patients, clients or employees in British Columbia, privacy law applies to you, even if you’re a small team. For most private businesses in BC, that law is the Personal Information Protection Act, known as PIPA. This article explains what PIPA means for your technology in practical terms and gives you a checklist you can work through.

Important: this is general information from an IT perspective, not legal advice. Privacy obligations depend on your industry and circumstances, so talk to a lawyer or privacy professional about your specific situation. The Office of the Information and Privacy Commissioner for BC (OIPC) also publishes helpful guidance for organisations.

Which privacy law applies?

Canada has several privacy laws, and which one applies depends on who you are and what you do:

  • PIPA (BC) applies to most private-sector organisations operating in British Columbia, including businesses, charities and nonprofit societies, for personal information collected, used and disclosed within the province.
  • PIPEDA (federal) applies to federally regulated organisations, such as banks, airlines and telecommunications companies, and to personal information that crosses provincial or national borders in the course of commercial activity.
  • FOIPPA (BC) applies to public bodies like government ministries, health authorities and school districts, not to private businesses.

Some businesses may deal with more than one law, and certain professions have additional obligations from their regulatory bodies.

What PIPA expects, in plain English

PIPA sets out rules about how organisations collect, use, disclose and protect personal information. The key principles include:

  • Consent: collect, use and share personal information with the person’s consent, with some exceptions.
  • Reasonable purposes: only collect what you reasonably need for the purpose you’ve explained.
  • Access and correction: people can ask to see the information you hold about them and request corrections.
  • Accountability: designate someone responsible for privacy compliance and have policies in place.
  • Security safeguards: protect personal information with reasonable security arrangements against unauthorised access, collection, use, disclosure, copying, modification or disposal.
  • Retention: keep information only as long as needed, and destroy it securely afterwards.

That security requirement is where your IT comes in. The law doesn’t list specific technologies. “Reasonable” depends on how sensitive the information is and what could happen if it were exposed. A dental clinic’s patient records need stronger protection than a coffee shop’s loyalty email list.

The IT checklist

Work through these areas. Each one is a practical safeguard that helps demonstrate reasonable security.

1. Know what personal information you have and where it lives

  • List the types of personal information you collect: names, contact details, ID documents, health, financial, employee records.
  • Note where each is stored: practice software, email, file shares, cloud apps, paper, laptops, phones.
  • Identify which third-party services store or process it on your behalf.

You can’t protect what you don’t know about.

2. Control who can access it

  • Every person has their own login. No shared accounts.
  • Staff only have access to the information they need for their role.
  • Access is removed promptly when someone leaves or changes roles.
  • Administrator accounts are separate from everyday accounts and tightly protected.

3. Protect accounts with multi-factor authentication

  • MFA is enforced on email, cloud services, remote access and any system holding sensitive data.
  • Strong password practices are in place, ideally with a business password manager.

4. Secure your devices

  • Laptops and desktops have full-disk encryption, so a lost or stolen device doesn’t expose data.
  • Endpoint protection, ideally endpoint detection and response, is installed and monitored.
  • Operating systems and software are patched regularly.
  • Phones and tablets that access business data are managed or protected with app-level controls.
  • Screens lock automatically after a short period.

5. Protect your network and email

  • A properly configured business firewall is in place.
  • Guest Wi-Fi is separate from business systems.
  • Remote access uses a secure, MFA-protected method.
  • Email filtering blocks phishing and malware, and domain authentication (SPF, DKIM, DMARC) is configured.

6. Share information safely

  • Sensitive documents are shared through secure portals or encrypted links, not regular email attachments.
  • External sharing settings in Microsoft 365 or Google Workspace are restricted and reviewed.
  • Staff know how to verify who they’re sending information to.

7. Back it up securely

  • Personal information is backed up, and backups are encrypted.
  • At least one backup copy is protected from ransomware.
  • Restores are tested. Losing information can be a privacy problem too.

8. Keep records of who did what

  • Audit logging is enabled on key systems, such as Microsoft 365, practice software and file servers.
  • Logs are kept long enough to investigate an incident.

9. Retain and dispose of information properly

  • Retention periods are defined for different types of records.
  • Old data is deleted when it’s no longer needed.
  • Retired computers, drives and phones are securely wiped or destroyed.

10. Train your team

  • Staff receive regular security awareness training, including phishing.
  • People know how to report a lost device, a suspicious email or a possible breach.

11. Choose and manage vendors carefully

  • Cloud services and IT providers that handle personal information have appropriate security and contracts.
  • You know where your data is stored and who can access it.

12. Be ready for an incident

  • There’s a written plan for responding to a privacy breach or cyberattack.
  • Someone is responsible for deciding whether affected individuals or regulators need to be notified, with legal advice as needed.
  • Contact details for your IT provider, insurer and legal counsel are easy to find.

Breaches and notification

If personal information is lost, stolen or accessed without authorisation, act quickly to contain it and assess the risk of harm. Notification requirements differ between laws and have been changing, and federally regulated organisations and those subject to PIPEDA have mandatory breach reporting and record-keeping obligations in certain circumstances. Get legal advice on your specific obligations, and check the OIPC and the federal Privacy Commissioner’s websites for current guidance. Even when notification isn’t strictly required, telling affected people promptly is often the right thing to do and helps preserve trust.

Where to start

If that list feels long, prioritise. For most small businesses, the highest-impact steps are:

  1. Enforce multi-factor authentication everywhere.
  2. Encrypt laptops and keep devices patched.
  3. Remove shared accounts and old user access.
  4. Make sure backups exist, are encrypted and are tested.
  5. Train staff to recognise phishing.

Getting help

We help BC businesses put these safeguards in place and document them, so you can show clients, insurers and regulators what you’ve done. Learn more about our cybersecurity services or contact us for a practical review of your current setup.