🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA-BC · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

Canada – British Columbia

CA-BC schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 34 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, actively-enforced private-sector statute with a functioning independent regulator and confirmed federal 'substantially similar' status; recent joint enforcement (OpenAI, TikTok) demonstrates active jurisdiction.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — GreenComprehensive, actively-enforced private-sector statute with a functioning independent regulator and confirmed federal 'substantially similar' status; recent joint enforcement (OpenAI, TikTok) demonstrates active jurisdiction.

Sub-modules (5)

Regulator And AuthorityGreen

OIPC BC, led by Commissioner Michael Harvey as of May 2026, oversees PIPA (private sector), FIPPA (public sector), and the E-Health Act (health records).

Claims: CLM-CA-BC-a1b2c3d4, CLM-CA-BC-b2c3d4e5

Act And InstrumentsGreen

PIPA (SBC 2003, c. 63) is the operative private-sector instrument; FIPPA (RSBC 1996, c. 165) governs public bodies; the E-Health Act governs health-information custodians.

Claims: CLM-CA-BC-c3d4e5f6

Material ScopeGreen

PIPA applies to the collection, use and disclosure of personal information by private-sector organizations, including employee personal information, subject to statutory exclusions.

Claims: CLM-CA-BC-d4e5f6a7

Territorial ScopeGreen

PIPA applies to organizations' activity within BC; a real-and-substantial-connection test extends jurisdiction to non-established foreign controllers, as confirmed in the OpenAI and TikTok joint investigations.

Claims: CLM-CA-BC-e5f6a7b8, CLM-CA-BC-f6a7b8c9

Regulator Registration And FilingAmber

PIPA does not impose a general controller registration or filing requirement on organizations.

Absence provenance: not recorded. Searched: BC PIPA registration filing requirement OIPC.

Category narrative117 words

British Columbia's private-sector data protection regime is anchored in the Personal Information Protection Act (PIPA), SBC 2003, c. 63, overseen by the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC), currently led by Commissioner Michael Harvey. PIPA has been declared substantially similar to the federal PIPEDA, which carves BC-internal commercial/organizational personal-information handling out of PIPEDA's Part 1 via Exemption Order SOR/2004-220, while PIPEDA continues to govern interprovincial/international commercial transactions and federally-regulated works and undertakings (FWUBs). The OIPC BC also oversees the public-sector Freedom of Information and Protection of Privacy Act (FIPPA), RSBC 1996, c. 165, and the health-sector E-Health (Personal Health Information Access and Protection of Privacy) Act, giving it a tri-regime portfolio.

Sources and claims (6)
  1. ConfirmedOPC CanadaThe Information and Privacy Commissioner for British Columbia is responsible for overseeing and enforcing PIPA, FIPPA, and the E-Health Act.
  2. ConfirmedOPC CanadaMichael Harvey serves as the Information and Privacy Commissioner for British Columbia as of the May 2026 joint ChatGPT investigation announcement.
  3. ConfirmedOPC CanadaPIPA is BC's private-sector privacy law, and has been deemed 'substantially similar' to the federal PIPEDA, while FIPPA is BC's public-sector privacy law and the E-Health Act governs health records.
  4. ConfirmedOPC CanadaEmployee personal information held by provincially-regulated organizations in British Columbia is covered by PIPA, unlike PIPEDA which excludes employee information for non-FWUB organizations.
  5. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIExemption Order SOR/2004-220, issued under PIPEDA, exempts organizations from Part 1 of PIPEDA for collection, use, or disclosure of personal information occurring within British Columbia, making PIPA the operative statute for BC-internal activity even for organizations without physical presence in Canada.
  6. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIThe OIPC-BC and the BC Court of Appeal have confirmed that PIPA's jurisdiction extends to foreign organizations with a real and substantial connection to British Columbia, notwithstanding lack of establishment or employees in Canada prior to product launch.

#

Core consent architecture is robust and enforced, but the absence of a codified sensitive-data category and of anonymisation safe-harbours leaves gaps relative to GDPR-style regimes.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberCore consent architecture is robust and enforced, but the absence of a codified sensitive-data category and of anonymisation safe-harbours leaves gaps relative to GDPR-style regimes.

Sub-modules (4)

Lawful BasesGreen

Consent is the primary lawful basis under ss. 6-8 of PIPA, subject to enumerated exceptions; collection/use/disclosure must additionally satisfy the 'reasonable purpose' test.

Claims: CLM-CA-BC-g7h8i9j0, CLM-CA-BC-h8i9j0k1

Special CategoriesAmber

PIPA has no express statutory 'special category' list, but biometric/facial-recognition data has been found by joint regulatory investigations to be sensitive in almost all circumstances, generally triggering an express-consent requirement.

Claims: CLM-CA-BC-j0k1l2m3

Pseudonymisation And AnonymisationRed

No statutory definitions or safe-harbour provisions for pseudonymisation or anonymisation exist under PIPA.

Absence provenance: not recorded. Searched: BC PIPA pseudonymisation anonymisation definition safe harbour.

Category narrative72 words

PIPA operates on a consent-based model (ss. 6-8) coupled with a 'reasonable purpose' appropriateness test (ss. 11 and 14) that must be satisfied regardless of consent. There is no GDPR Art 9-style enumerated special-category list on the face of the statute, but joint OPC/OIPC-BC/OIPC-AB guidance and case law (Clearview AI, Cadillac Fairview) treat biometric information as inherently sensitive, generally requiring express consent. PIPA contains no statutory definitions of pseudonymisation or anonymisation safe-harbours.

Sources and claims (4)
  1. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAISections 6-8 of PIPA-BC require the consent of individuals for the collection, use or disclosure of their personal information, unless an exception applies.
  2. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIAn organization may collect, use or disclose personal information under PIPA only for a purpose that a reasonable person would consider appropriate in the circumstances, per sections 11 and 14.
  3. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIJoint guidelines issued by OPC, OIPC-AB and OIPC-BC provide that organizations must generally obtain express consent when information is sensitive, collection/use/disclosure is outside reasonable expectations, or creates a meaningful residual risk of significant harm.
  4. ConfirmedOPC Canada / OIPC AB / OIPC BCJoint regulatory investigations (Clearview AI, Cadillac Fairview) found biometric information to be sensitive in almost all circumstances, being intrinsically and often permanently linked to an individual, distinctive and difficult to change.

#

Core access/correction rights are in force and enforced, but PIPA lacks GDPR-equivalent erasure, restriction/objection, and portability rights, which remain at the recommendation stage only.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberCore access/correction rights are in force and enforced, but PIPA lacks GDPR-equivalent erasure, restriction/objection, and portability rights, which remain at the recommendation stage only.

Sub-modules (5)

Access RightGreen

Individuals may request access to personal information about them held by an organization, subject to enumerated exceptions.

Claims: CLM-CA-BC-k1l2m3n4

Rectification And ErasureAmber

PIPA provides a correction right for inaccurate/incomplete information; a standalone erasure/'right to be forgotten' is not currently codified and was flagged by the OIPC as a reform priority going further than the federal C-11 proposal.

Claims: CLM-CA-BC-l2m3n4o5

Restriction And ObjectionRed

PIPA does not contain a general statutory right to restrict processing or object to processing/profiling; automated-decision-making transparency was among the OIPC's 12 reform recommendations, not yet enacted.

Claims: CLM-CA-BC-m3n4o5p6

Data PortabilityRed

PIPA does not currently include a data-portability right; portability was one of the OIPC's 12 PIPA-reform recommendations.

Claims: CLM-CA-BC-n4o5p6q7

Deadlines And Response WindowsAmber

PIPA requires organizations to respond to access requests within a defined statutory window; exact day-count was not independently re-verified against the current consolidated statute text in this research pass.

Absence provenance: not recorded. Searched: BC PIPA access request response deadline days section.

Category narrative75 words

PIPA provides individuals a right of access to their own personal information held by an organization and a right to request correction of inaccurate or incomplete information. PIPA does not currently contain an explicit right to erasure/be-forgotten, a general right to restrict or object to processing, or a data-portability right; the BC Special Committee's December 2021 reform report recommended adding several of these rights, but as of this run they remain proposed rather than enacted.

Sources and claims (4)
  1. ConfirmedOPC CanadaIndividuals have a right to know the details of unauthorized access of their personal information and, more broadly, a right to access personal information held about them by an organization subject to statutory exceptions.
  2. ConfirmedOPC CanadaThe OIPC BC's PIPA-reform recommendations included a 'Right to be Forgotten' proposal on which the federal OPC stated it would go further than the BC recommendation.
  3. ConfirmedOPC CanadaAutomated decision-making transparency was among the 12 recommendations made by the OIPC BC for PIPA reform, indicating it is not currently a codified right under PIPA.
  4. ConfirmedOPC CanadaData portability was among the 12 recommendations made by the OIPC BC for PIPA reform, confirming it is not a currently codified statutory right.

#

Accountability and security-safeguard obligations are in force, but the absence of mandatory breach notification and of explicit processor/service-provider accountability are material, long-flagged gaps relative to peer Canadian regimes and GDPR.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberAccountability and security-safeguard obligations are in force, but the absence of mandatory breach notification and of explicit processor/service-provider accountability are material, long-flagged gaps relative to peer Canadian regimes and GDPR.

Sub-modules (7)

Accountability And DpiaAmber

PIPA embeds an accountability principle requiring organizations to designate a person accountable for compliance; no formal DPIA-trigger regime is codified.

Claims: CLM-CA-BC-o5p6q7r8

Dpo RequirementsAmber

PIPA does not mandate formal DPO appointment thresholds; organizations must designate an accountable individual for compliance purposes.

Claims: CLM-CA-BC-o5p6q7r8

Ropa RequirementsRed

No express Records-of-Processing-Activities obligation is codified in PIPA.

Absence provenance: not recorded. Searched: BC PIPA records of processing activities requirement.

Joint Controller ArrangementsAmber

PIPA does not currently expressly hold organizations responsible for personal information transferred to a service provider for processing; the OIPC has recommended amending PIPA to impose such accountability, aligning with the federal Bill C-11/CPPA approach.

Claims: CLM-CA-BC-p6q7r8s9

Security MeasuresGreen

PIPA requires organizations to protect personal information under their control with reasonable security safeguards.

Claims: CLM-CA-BC-q7r8s9t0

Breach NotificationRed

PIPA does not impose a mandatory breach-notification requirement, making BC the outlier among Canadian 'substantially similar' regimes (PIPEDA, Alberta PIPA, Quebec's Private Sector Act) that all mandate breach reporting. The OIPC has repeatedly recommended mandatory notification be added; the April 2026 OIPC SME breach-response guide is non-binding guidance rather than a statutory notification duty.

Claims: CLM-CA-BC-r8s9t0u1, CLM-CA-BC-s9t0u1v2, CLM-CA-BC-t0u1v2w3

Retention And DisposalGreen

PIPA requires personal information to be retained only as long as necessary to fulfil the identified purpose, with disposal obligations thereafter.

Claims: CLM-CA-BC-u1v2w3x4

Category narrative114 words

PIPA imposes an accountability principle requiring organizations to designate an individual accountable for compliance, and requires reasonable security safeguards for personal information in an organization's custody or control. Critically, PIPA does not currently impose a mandatory breach-notification obligation on organizations or individuals — British Columbia is the one Canadian jurisdiction (among PIPEDA, Alberta PIPA, and Quebec's Private Sector Act) without mandatory breach reporting, despite the OIPC's repeated recommendations to add it. PIPA also does not expressly hold organizations accountable for personal information transferred to third-party service providers, another gap flagged by the OIPC for reform. The April 2026 OIPC breach-response guide for SMEs is non-binding operational guidance, not a codification of a mandatory-notification duty.

Sources and claims (7)
  1. ConfirmedOPC CanadaAn organization is responsible for personal information under its control and shall designate an individual or individuals accountable for the organization's compliance with core privacy principles.
  2. ConfirmedOIPC BCPIPA currently does not expressly hold organizations responsible for the personal information they transfer to a service provider, and the OIPC has recommended amending PIPA to require contractual or other means ensuring compliance or comparable protection.
  3. ConfirmedOPC CanadaPIPA requires organizations to protect personal information in their custody or under their control through reasonable security arrangements against risks such as unauthorized access, collection, use, or disclosure.
  4. ConfirmedOPC CanadaThe BC OIPC has recommended that PIPA be amended to require organizations to notify affected individuals and the Commissioner of any loss of, unauthorized access to, or disclosure of personal information where it is reasonable to believe there is a real risk of significant harm — confirming this is not yet a binding statutory requirement.
  5. ConfirmedIAPPQuebec's mandatory breach reporting to its data protection authority and to individuals is described as bringing that province's regime into alignment with 'the existing regime everywhere else in Canada, except British Columbia', confirming BC PIPA lacks a mandatory breach-notification obligation.
  6. ConfirmedDataGuidanceIn April 2026, the OIPC BC published a quick-reference guide for small and medium-sized businesses on responding to privacy breaches, explaining that a privacy breach occurs when personal information is mishandled in violation of PIPA and describing OIPC's monitoring and recommendation role, without imposing a new mandatory notification duty.
  7. ProbableOPC CanadaOrganizations are expected to limit collection to what is necessary and retain personal information only as long as necessary to fulfil identified purposes under BC and Alberta's private-sector privacy laws.

#

Private-sector transfer mechanics are well-settled via the PIPEDA/PIPA interlock, but the 2021 removal of BC's public-sector data-residency mandate in favour of yet-unspecified regulations creates ongoing uncertainty flagged by the regulator itself.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63 / Freedom of Information and Protection of Privacy Act, RSBC 1996, c. 165
Traffic-light rationale — AmberPrivate-sector transfer mechanics are well-settled via the PIPEDA/PIPA interlock, but the 2021 removal of BC's public-sector data-residency mandate in favour of yet-unspecified regulations creates ongoing uncertainty flagged by the regulator itself.

Sub-modules (6)

Transfer MechanismsGreen

Trans-border commercial personal-information flows by BC organizations are governed by PIPEDA under the federal government's trade-and-commerce power, even where PIPA otherwise applies to in-province activity.

Claims: CLM-CA-BC-v2w3x4y5

Adequacy ReceivedAmber

Not applicable as a discrete BC-level adequacy decision; BC's regime is recognized federally as 'substantially similar' to PIPEDA rather than receiving adequacy from a foreign regulator.

Absence provenance: not recorded. Searched: British Columbia PIPA foreign adequacy decision received.

Claims: CLM-CA-BC-w3x4y5z6

Adequacy GrantedAmber

BC does not independently grant adequacy decisions; this function does not exist at the provincial level in Canada.

Absence provenance: not recorded. Searched: British Columbia PIPA adequacy granted to other jurisdictions.

Sccs And BcrsAmber

PIPA does not prescribe SCC- or BCR-style standardized transfer instruments; contractual accountability for transferred data is currently a policy recommendation rather than a codified requirement.

Claims: CLM-CA-BC-p6q7r8s9

Transfer Impact AssessmentRed

No TIA-equivalent requirement is codified in PIPA.

Absence provenance: not recorded. Searched: BC PIPA transfer impact assessment requirement.

Data LocalisationAmber

BC's public-sector FIPPA formerly required public bodies to store and access personal information only in Canada (s. 30.1); Bill 22 (2021) replaced this prohibition with a regulation-dependent disclosure permission, in practice removing the data-residency mandate, a change the OIPC BC criticized.

Claims: CLM-CA-BC-x4y5z6a7, CLM-CA-BC-y5z6a7b8, CLM-CA-BC-z6a7b8c9

Category narrative105 words

PIPA governs BC-internal personal information flows, while PIPEDA continues to apply to interprovincial and international commercial transfers and to federally-regulated works and undertakings even within BC. BC has no formal 'adequacy' regime of its own analogous to GDPR Art 45; rather, it participates in Canada's internal 'substantially similar' recognition scheme. For the public sector, FIPPA formerly imposed an absolute Canada-only data-residency/data-access mandate (s. 30.1), but the Freedom of Information and Protection of Privacy Amendment Act, 2021 (Bill 22) replaced this prohibition with a regulation-dependent approach, in practice removing the hard data-residency requirement — a change the OIPC BC publicly criticized for its lack of transparency.

Sources and claims (5)
  1. ConfirmedOPC CanadaTrans-border personal information flows in a commercial context are covered by PIPEDA due to the federal government's constitutional power over inter-provincial and international trade and commerce, even for organizations otherwise subject to PIPA.
  2. ConfirmedOPC CanadaPIPA has been declared substantially similar to PIPEDA, the mechanism by which BC's private-sector regime is recognized as equivalent within Canada's federal-provincial privacy architecture.
  3. ConfirmedIAPPSection 30.1 of the BC Freedom of Information and Protection of Privacy Act formerly required public bodies to ensure personal information in their custody or control was stored only in Canada and accessed only in Canada.
  4. ConfirmedIAPPThe Freedom of Information and Protection of Privacy Amendment Act, 2021 (Bill 22) replaced the prohibition on disclosure of personal information outside Canada with a provision allowing such disclosure in accordance with regulations, in practical terms removing the data-residency requirement.
  5. ConfirmedDataGuidanceThe OIPC BC wrote to the responsible Minister expressing concern that Bill 22's data-residency changes would be filled in only through regulations whose substance was unknown at the time of the bill's introduction.

#

Health and employment overlays are well-documented and in force; several other sectoral sub-modules show no BC-specific overlay, which is itself a legitimate finding rather than a research gap.

Primary frameworkE-Health (Personal Health Information Access and Protection of Privacy) Act / Personal Information Protection Act (PIPA)
Traffic-light rationale — AmberHealth and employment overlays are well-documented and in force; several other sectoral sub-modules show no BC-specific overlay, which is itself a legitimate finding rather than a research gap.

Sub-modules (7)

Financial Sector OverlayAmber

No BC-specific financial-sector privacy overlay distinct from PIPA was identified; federally-regulated financial institutions (banks) remain subject to PIPEDA as FWUBs, while BC-regulated credit unions fall under PIPA.

Absence provenance: not recorded. Searched: British Columbia financial sector data protection overlay PIPA credit union.

Health Sector OverlayGreen

The E-Health (Personal Health Information Access and Protection of Privacy) Act is BC's dedicated health-records privacy law, overseen by the OIPC BC.

Claims: CLM-CA-BC-a7b8c9d0

Telecoms And EprivacyAmber

No BC-specific ePrivacy/telecoms overlay distinct from PIPA/PIPEDA and the federal Anti-Spam Legislation (CASL) was identified.

Absence provenance: not recorded. Searched: British Columbia telecoms ePrivacy overlay PIPA.

Employment DataGreen

PIPA directly covers employee personal information held by provincially-regulated organizations, a notable distinction from PIPEDA's employee-information exclusion for non-FWUB organizations.

Claims: CLM-CA-BC-d4e5f6a7

Credit And ScoringAmber

No BC-specific credit-reporting or scoring statute distinct from general PIPA obligations was identified.

Absence provenance: not recorded. Searched: British Columbia credit reporting scoring privacy statute.

EducationAmber

No BC-specific private-sector education-privacy overlay distinct from PIPA/FIPPA was identified in this pass, though federal/provincial regulators have jointly addressed education-technology privacy concerns for minors.

Absence provenance: not recorded. Searched: British Columbia education sector privacy overlay PIPA FIPPA.

InsuranceAmber

No BC-specific insurance-sector privacy overlay distinct from general PIPA obligations was identified.

Absence provenance: not recorded. Searched: British Columbia insurance sector privacy overlay PIPA.

Category narrative72 words

BC's DP landscape includes a dedicated health-sector overlay (the E-Health (Personal Health Information Access and Protection of Privacy) Act) administered by the same OIPC BC, and an employment overlay embedded directly within PIPA itself (unlike PIPEDA, which excludes employee data for non-FWUB organizations). No BC-specific financial-sector, telecoms/ePrivacy, credit-scoring, education, or insurance-specific privacy overlay statutes were identified distinct from general PIPA/FIPPA coverage; federally-regulated financial institutions and telecoms remain subject to PIPEDA as FWUBs.

Sources and claims (1)
  1. ConfirmedOPC CanadaThe Information and Privacy Commissioner for British Columbia oversees the E-Health (Personal Health Information Access and Protection of Privacy) Act, BC's privacy law relating to health records.

#

No BC-specific adtech statute exists; coverage relies entirely on PIPA's general consent/purpose principles, which is a materially thinner regime than jurisdictions with dedicated adtech rules (e.g., US-CA CPRA).

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — RedNo BC-specific adtech statute exists; coverage relies entirely on PIPA's general consent/purpose principles, which is a materially thinner regime than jurisdictions with dedicated adtech rules (e.g., US-CA CPRA).

Sub-modules (6)

Cookies And TrackersAmber

No BC-specific cookie-consent statute exists; general PIPA consent/purpose principles apply to online tracking by BC-regulated organizations.

Claims: CLM-CA-BC-h8i9j0k1

Dark PatternsRed

No codified dark-pattern prohibition exists under PIPA.

Absence provenance: not recorded. Searched: British Columbia PIPA dark patterns prohibition.

Opt Out SignalsRed

PIPA does not recognize a codified universal opt-out signal (e.g., Global Privacy Control) mechanism.

Absence provenance: not recorded. Searched: British Columbia PIPA Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rules exist under PIPA.

Absence provenance: not recorded. Searched: British Columbia PIPA data clean room rules.

Cross Context AdvertisingAmber

PIPA has no CPRA-style 'sale'/'share' construct for cross-context advertising; general consent/purpose-limitation rules apply instead.

Claims: CLM-CA-BC-h8i9j0k1

Direct MarketingAmber

Direct marketing by BC organizations is subject to PIPA's general consent principles and, separately, to the federal Anti-Spam Legislation (CASL) for electronic messages, which sits outside PIPA proper.

Claims: CLM-CA-BC-g7h8i9j0

Category narrative57 words

PIPA applies general consent and purpose-limitation principles to cookie/tracker use, direct marketing, and cross-context data use, but BC has no dedicated cookie-consent statute, no codified dark-pattern prohibition, no recognition regime for opt-out signals (e.g., Global Privacy Control), and no clean-room/data-collaboration-specific rules. Direct marketing is additionally governed federally by Canada's Anti-Spam Legislation (CASL), outside this JID's PIPA scope.

#

Strong, recent case-law-driven biometric protection exists via joint enforcement, but statutory ADM-transparency, genetic-data, and AI-risk-assessment provisions remain absent or only proposed.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberStrong, recent case-law-driven biometric protection exists via joint enforcement, but statutory ADM-transparency, genetic-data, and AI-risk-assessment provisions remain absent or only proposed.

Sub-modules (6)

Profiling RestrictionsRed

No Art 22-style profiling restriction is codified in PIPA; automated decision-making was flagged in the OIPC's 2021 reform recommendations as an area for legislative change.

Claims: CLM-CA-BC-m3n4o5p6

Automated Decision Making TransparencyRed

No statutory ADM-transparency or explanation right currently exists under PIPA; this remains a pending reform recommendation.

Claims: CLM-CA-BC-m3n4o5p6

Ai Risk AssessmentsAmber

PIPA has no AI-specific risk-assessment requirement; the 2026 joint OpenAI/ChatGPT investigation applied PIPA's general consent and purpose-limitation framework to generative-AI data practices rather than a dedicated AI statute.

Claims: CLM-CA-BC-b8c9d0e1

Biometric RegimeAmber

Biometric information, including facial-recognition data, has been found by joint regulatory investigations to be sensitive information generally requiring express consent under PIPA's consent framework.

Claims: CLM-CA-BC-j0k1l2m3, CLM-CA-BC-c9d0e1f2

Genetic DataRed

No BC-specific genetic-data regime distinct from PIPA's general sensitive-information treatment was identified.

Absence provenance: not recorded. Searched: British Columbia PIPA genetic data regime.

State Surveillance CarveoutsAmber

PIPA permits disclosure without consent to government institutions/investigative bodies in defined law-enforcement and national-security circumstances; the scope of these voluntary-disclosure exceptions was itself flagged for review by the OIPC, FIPA and OpenMedia during the 2021 PIPA reform consultation.

Claims: CLM-CA-BC-d0e1f2g3

Category narrative84 words

PIPA has no codified Art 22-style profiling-restriction or ADM-transparency right; automated decision-making was one of the OIPC's 12 PIPA-reform recommendations, not yet enacted. Biometric data, however, has been substantively addressed through joint enforcement: the Clearview AI and Cadillac Fairview investigations found facial-recognition/biometric data to be sensitive information generally requiring express consent, and the 2026 OpenAI/ChatGPT joint investigation extended scrutiny to generative-AI training-data practices under PIPA. No BC-specific genetic-data statute or AI-specific risk-assessment law exists; national-security carve-outs are addressed generally through PIPA's law-enforcement disclosure exceptions.

Sources and claims (3)
  1. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIIn 2026, the OPC, CAI, OIPC-BC, and OIPC-AB jointly released findings on OpenAI's ChatGPT, examining compliance with PIPEDA, Quebec's Private Sector Act, PIPA-BC and PIPA-AB rather than any dedicated AI-specific statute.
  2. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIA joint investigation found that Clearview AI's collection of images and creation of biometric facial-recognition arrays required assessment against PIPA-BC's and PIPA-AB's reasonable-purpose and consent requirements.
  3. ConfirmedIAPPThe OIPC, FIPA and OpenMedia.ca called for the PIPA Special Committee to review PIPA's provisions permitting organizations to voluntarily provide information to law enforcement, with FIPA recommending that law enforcement be required to provide evidence of lawful authority to compel production.

#

No codified statutory age-of-consent or parental-consent regime exists, but active, recent joint enforcement (TikTok 2025) demonstrates the regulator applying general consent principles rigorously to protect minors.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberNo codified statutory age-of-consent or parental-consent regime exists, but active, recent joint enforcement (TikTok 2025) demonstrates the regulator applying general consent principles rigorously to protect minors.

Sub-modules (5)

Age VerificationAmber

PIPA does not codify a statutory age-verification requirement; consent capacity for minors is assessed contextually.

Claims: CLM-CA-BC-e1f2g3h4

Minor Profiling BansRed

No BC-specific statutory ban on profiling minors exists; the TikTok joint investigation instead applied general consent/purpose-appropriateness rules.

Claims: CLM-CA-BC-e1f2g3h4

Education SettingsAmber

Federal, provincial and territorial commissioners, including OIPC BC's counterparts, jointly issued a resolution on protecting children's privacy in classroom educational-technology use, though this is guidance rather than binding BC-specific legislation.

Claims: CLM-CA-BC-f2g3h4i5

Dependent AdultsRed

No BC-specific dependent-adults privacy provision distinct from PIPA's general framework was identified.

Absence provenance: not recorded. Searched: British Columbia PIPA dependent adults privacy protection.

Category narrative73 words

PIPA contains no codified age-of-consent threshold or parental-consent mechanism analogous to COPPA or GDPR Art 8; consent validity for minors is instead assessed contextually via the 'meaningful consent' standard, considering cognitive ability and developmental maturity, as applied in the 2025 joint TikTok investigation which found consent practices for 13-17-year-old users inadequate. No BC-specific minor-profiling ban, education-settings-specific statute, or dependent-adults-specific privacy provision was identified beyond PIPA's general framework and FIPPA's coverage of public schools.

Sources and claims (2)
  1. ConfirmedOPC Canada / OIPC BC / OIPC AB / CAIIn the 2025 joint TikTok investigation, the Offices found that TikTok's collection and use of personal information from underage users (many aged 13-17) was inappropriate, unreasonable and illegitimate, contravening sections 11 and 14 of PIPA BC among other provisions, given the platform's sophisticated age-estimation analytics used for other business purposes.
  2. ConfirmedOPC CanadaCommissioner Dufresne and privacy authorities from across Canada, including BC's counterpart, issued a joint resolution on protecting the privacy of children and youth in the classroom through responsible educational technologies.

#

Order-making powers are real and recently exercised via major joint AI/platform investigations, but the absence of AMPs constrains the deterrent strength of BC's enforcement regime relative to Quebec, the federal CPPA proposal, and GDPR-style regimes.

Primary frameworkPersonal Information Protection Act (PIPA), SBC 2003, c. 63
Traffic-light rationale — AmberOrder-making powers are real and recently exercised via major joint AI/platform investigations, but the absence of AMPs constrains the deterrent strength of BC's enforcement regime relative to Quebec, the federal CPPA proposal, and GDPR-style regimes.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Commissioner holds order-making powers under s. 52 of PIPA but lacks authority to impose financial/administrative monetary penalties, a gap the OIPC has repeatedly asked the legislature to close.

Claims: CLM-CA-BC-g3h4i5j6, CLM-CA-BC-h4i5j6k7

Enforcement Activity IndexGreen

Recent joint investigations (OpenAI 2026, TikTok 2025, Clearview AI 2021, Cadillac Fairview 2020) demonstrate sustained, high-profile OIPC BC enforcement activity in coordination with federal and other provincial regulators.

Claims: CLM-CA-BC-b8c9d0e1, CLM-CA-BC-e1f2g3h4

Regulator Funding And CapacityAmber

No specific BC OIPC budget/headcount figures were located in this research pass; capacity is evidenced indirectly through sustained participation in multi-regulator joint investigations.

Absence provenance: not recorded. Searched: OIPC BC budget headcount funding capacity 2026.

Collective Redress And Class ActionsAmber

No PIPA-specific class-action mechanism was identified beyond BC's general Class Proceedings Act civil framework.

Absence provenance: not recorded. Searched: British Columbia PIPA class action collective redress mechanism.

Private Right Of ActionAmber

PIPA's enforcement model centers on Commissioner complaint/investigation/order processes rather than a direct private right of court action, though general civil remedies may be available outside the Act.

Absence provenance: not recorded. Searched: British Columbia PIPA private right of action civil suit.

Recent Developments 180DGreen

Within the last 180 days, the OIPC BC (i) co-published the May 2026 joint findings on OpenAI/ChatGPT with the federal OPC, CAI and Alberta OIPC, and (ii) published an April 2026 SME privacy-breach quick-reference guide.

Claims: CLM-CA-BC-b8c9d0e1, CLM-CA-BC-t0u1v2w3

Category narrative99 words

The OIPC BC holds order-making powers under PIPA s. 52 but, unlike Alberta's Lobbyists Transparency Act model the OIPC also administers, PIPA carries no administrative-monetary-penalty (AMP) regime; the OIPC has repeatedly and unsuccessfully sought AMP authority through the 2021 PIPA reform process. Enforcement activity in the trailing 12-18 months has been substantial via cross-Canada joint investigations: the 2026 OpenAI/ChatGPT findings (announced May 6, 2026) and the 2025 TikTok findings, both conducted jointly with the federal OPC, Quebec's CAI, and Alberta's OIPC. No BC-specific class-action or private-right-of-action mechanism distinct from general BC civil procedure and PIPA's complaint/order framework was identified.

Sources and claims (2)
  1. ConfirmedOPC CanadaThe OIPC currently has order-making powers under section 52 of PIPA.
  2. ConfirmedOPC CanadaThe OIPC has argued its order-making power is 'inadequate' because it lacks the ability to issue financial penalties, and has recommended PIPA be amended to enable the Commissioner to impose administrative monetary penalties, noting its existing experience administering AMPs under BC's Lobbyists Transparency Act.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada – British Columbia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s), 20 source(s) in the cumulative register.