Does a BC company have to report a breach?
Three different instruments get mixed together in this question, and they give three different answers. Which one binds you decides what you actually have to do.
The short version
- Federally regulated or handling personal information in commercial activity across provincial lines — PIPEDA. There is a mandatory reporting duty where a breach creates a real risk of significant harm, plus a duty to keep records of breaches.
- A BC private-sector organization or non-profit under BC PIPA. The Act requires reasonable security arrangements. It does not impose a mandatory breach-notification duty. Reporting to the Office of the Information and Privacy Commissioner is voluntary.
- A BC public body under FIPPA. Mandatory notification to the affected individual and to the Commissioner, in force since 1 February 2023 under FIPPA s. 36.3, where the breach “could reasonably be expected to result in significant harm”, without unreasonable delay. It usually reaches suppliers through the contract schedule.
The claim that is wrong
You will find pages asserting that BC PIPA was amended in 2023 to add mandatory breach notification, “bringing it in line with PIPEDA and the other provinces.” That is not supported by the statute. The OIPC's own material treats mandatory breach notification as a reform it has recommended — which is the opposite of it already being law.
It is worth being precise about where that claim comes from, because the half of it that is true is what makes it so durable. British Columbia did enact mandatory breach notification, and it did commence on 1 February 2023 — but in FIPPA s. 36.3, added by the Freedom of Information and Protection of Privacy Amendment Act, 2021, and it binds public bodies. PIPA, which is the Act that binds private-sector organizations and non-profits, was not amended and still contains no notification duty; it requires reasonable security arrangements and nothing more. So “BC”, “mandatory breach notification” and “2023” are each true, and the conclusion drawn from them is still wrong. The question that decides it is which Act you are under, which is the whole point of the list above.
This matters commercially, not just pedantically. If you buy a compliance programme sold to you on the basis of a BC notification deadline, you have bought against a duty that does not exist in that form. The real pressure on BC private-sector organizations is contractual: your customers, your insurer, and procurement.
What to do instead
Work out which instrument binds you, then work backwards from the document that is actually going to be read — the insurance application, the vendor questionnaire, the procurement schedule. Those have deadlines and consequences that are concrete today. Build the breach procedure because a breach is genuinely likely and because your contracts require it, not because of a BC statutory clock that has not been enacted.
Voluntary reporting to the OIPC still has a purpose: it is one of the ways an organization demonstrates that it took the matter seriously.