📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

What is BC FIPPA

What is BC FIPPA (Freedom of Information and Protection of Privacy Act)?

BC FIPPA is British Columbia's public-sector privacy and access law. It applies to ministries, municipalities, health authorities, school boards, universities, Crown corporations, and the service providers that work for them. Since 1 February 2023 it has required every public body to run a privacy management program and to report serious privacy breaches.

Map your BC FIPPA controls See the core components

RSBC 1996, c. 165 · privacy management programs · breach notification since 1 Feb 2023 · enforced by the BC OIPC

Definition

The Freedom of Information and Protection of Privacy Act (FIPPA, sometimes written FOIPPA) is the British Columbia statute that governs how public bodies handle personal information and how the public can request their records. It has two halves: access to information, and protection of privacy.

FIPPA applies to provincial ministries, municipalities and regional districts, Crown corporations, school boards, health authorities and public hospitals, universities and colleges, municipal police, and self-governing professional bodies. Private organizations in BC fall under BC PIPA instead, and designated provincial health information banks are also governed by the BC E-Health Act.

The Act changed substantially in November 2021. The amendments removed the general requirement to store personal information in Canada, added a privacy management program requirement and mandatory breach notification (both in force since 1 February 2023), and created new offences for unauthorized collection, use, and disclosure.

The Office of the Information and Privacy Commissioner for British Columbia (OIPC) oversees FIPPA, investigates complaints, and reviews access decisions.

Core components

Privacy management program

Since 1 February 2023, every public body must keep a documented program: who is responsible for privacy, policies, training, privacy impact assessments, breach response, and regular review.

Mandatory breach notification

A public body must notify affected people and the OIPC without unreasonable delay when a breach could reasonably be expected to cause significant harm.

Privacy impact assessments

Required for every new or changed initiative involving personal information, with a documented risk assessment before sensitive personal information is stored outside Canada.

Reasonable security arrangements

Public bodies must protect personal information against risks such as unauthorized access, collection, use, disclosure, or disposal. In practice that means access control, logging, patching, and monitoring you can show evidence for.

Service providers

Contractors that handle personal information for a public body, including IT and managed service providers, are bound by FIPPA's privacy rules, usually through a privacy protection schedule in the contract.

Offences and OIPC oversight

Unauthorized collection, use, or disclosure, including snooping in records, is an offence with fines of up to $50,000 for individuals and $500,000 for corporations. The OIPC investigates complaints and reviews access decisions.

Why it matters

For MSPs and IT providers serving BC municipalities, school districts, health authorities, and other public bodies, FIPPA is the contract. Procurement teams ask for a privacy impact assessment, evidence of security arrangements, breach detection that can meet the notification duty, and a clear answer on where data is stored.

The 2021 amendments made cloud services easier to use, but they did not make them automatic. A public body still has to assess sensitive information stored outside Canada, and many still prefer Canadian hosting because it makes that assessment short.

The snooping offences put authorized users in scope too. Audit logs that show who looked at what, and alerts on unusual access, are now part of showing reasonable security.

How Lavawall® helps with BC FIPPA

Lavawall® includes BC FIPPA as its own framework, alongside the BC E-Health Act (listed as BC HIA), BC PIPA, PIPEDA, and Alberta's public-sector privacy law. Answers write to shared controls, so evidence collected once counts toward every framework a client needs.

Microsoft 365 and Google Workspace breach detection, file and SharePoint access monitoring, patching, and configuration assessments produce the security-arrangement and breach-detection evidence that FIPPA procurement and privacy management programs ask for.

Lavawall® is hosted in Canada (AWS Montréal by default, moving to a Canadian-owned hosting provider in Vancouver in Q4 2026), which keeps the outside-Canada part of a public body's privacy impact assessment simple.

Start your BC FIPPA mapping →

Frequently asked

What is BC FIPPA?
The Freedom of Information and Protection of Privacy Act (RSBC 1996, c. 165), British Columbia's public-sector privacy and access law. It gives the public a right to request records from public bodies and sets the rules those bodies must follow when they collect, use, disclose, and protect personal information. It is sometimes written FOIPPA.
Who does BC FIPPA apply to?
BC public bodies: provincial ministries, municipalities, Crown corporations, school boards, health authorities, universities and colleges, municipal police, and self-governing professional bodies. The contractors and service providers that handle personal information for them, including MSPs, take on FIPPA obligations through their contracts and the Act itself.
Does BC FIPPA require breach notification?
Yes. Since 1 February 2023, a public body must notify affected people and the BC OIPC without unreasonable delay when a privacy breach could reasonably be expected to cause significant harm.
Does BC FIPPA still require data to be stored in Canada?
No. The 2021 amendments removed the general requirement to keep personal information in Canada. Public bodies must still complete a privacy impact assessment for every initiative, and a documented risk assessment before sensitive personal information is stored outside Canada.
What is a privacy management program under FIPPA?
A documented program every public body has had to maintain since 1 February 2023. It covers who is responsible for privacy, policies, training, privacy impact assessments, breach response, and regular review.
How is BC FIPPA different from BC PIPA and the BC E-Health Act?
FIPPA covers public bodies. BC PIPA covers private organizations, including private health practices. The BC E-Health Act, often searched for as BC HIA, covers designated provincial health information banks. All three are enforced by the BC OIPC.