A guide for British Columbia public bodies

British Columbia's privacy impact assessments: what section 69 of FOIPPA and the minister's directions require of every public body

BC wrote the PIA into its statute before any other province and then, in 2021, added a privacy management program, mandatory breach notification and new directions on when an assessment is due. What the Act says, what the directions add, how ministries and other public bodies differ, and where each element lives in AccessPoint — for privacy officers, records managers and the program leads whose initiative cannot start without one.

Section 69(5) of British Columbia's Freedom of Information and Protection of Privacy Act requires the head of a ministry to conduct a privacy impact assessment in accordance with the minister's directions, and section 69(5.3) requires the same of the head of every other public body. The directions in force since November 26, 2021 make an assessment due on any new initiative and before any significant change to an existing one; ministries submit during development for the minister's review, and common or integrated programs are notified to the Commissioner. Beside the PIA sit section 36.2's privacy management program and section 36.3's breach notification to individuals and the Commissioner.

British Columbia is the reference case for a statutory PIA regime in Canada: the duty has been in FOIPPA long enough that most public bodies have a template, a privacy officer and a filing habit. The 2021 amendments changed the shape of the obligation more than its existence, and the parts that catch organizations now are the ones added then: the substantial-change trigger, the offshoring supplement, the privacy management program the PIA process must belong to, and a breach rule with a defined harm test. This guide sets out the current text, the current directions, and how the pieces fit.

What the Act says

FOIPPA defines a privacy impact assessment as "an assessment that is conducted by a public body to determine if a current or proposed enactment, system, project, program or activity meets or will meet the requirements of Part 3 of this Act". The duties sit in section 69:

  • 69(5) — the head of a ministry must conduct a PIA and must do so in accordance with the directions of the minister responsible for the Act.
  • 69(5.1) — for a proposed enactment, system, project, program or activity, the head of a ministry must submit the PIA to the minister responsible for the Act, during development, for the minister's review and comment.
  • 69(5.2) — where a ministry's PIA concerns a common or integrated program or activity, the minister must notify the Commissioner during development and, on request, make the PIA available for the Commissioner's review and comment.
  • 69(5.3) — the head of a public body that is not a ministry must conduct a PIA in accordance with the minister's directions.
  • 69(5.4) — for a proposed common or integrated program or activity, the head of a non-ministry public body must notify the Commissioner during development and, on request, make the PIA available for review and comment.

Two more provisions round it out. Section 69(3)(c) puts ministries' PIAs into the personal information directory the minister publishes, so a ministry's assessments are a matter of public record in summary. And ministries that are health care bodies must also assess their health information banks and health information-sharing agreements.

What the directions add

The minister's directions, issued separately to heads of ministries under section 69(5) and to heads of other public bodies under section 69(5.3), took effect on November 26, 2021. They define an initiative as an enactment, system, project, program or activity, and set the trigger:

  1. A PIA must be conducted on a new initiative for which no PIA has previously been conducted. For ministries, a previously conducted PIA includes one conducted in consultation with the minister on behalf of all or multiple ministries.
  2. A PIA must be conducted before implementing a significant change to an existing initiative, including but not limited to a change to the location in which sensitive personal information is stored when it is stored outside Canada.

The directions then walk through what the assessment must establish, including that personal information used to make a decision that directly affects an individual will be retained for at least one year after use, as section 31 of the Act requires, and they add a supplementary assessment for disclosures that store personal information outside Canada. For ministries, the directions restate the statute's timing: the PIA for a proposed initiative is submitted during the development phase, not at go-live.

The program the PIA belongs to

Privacy management program. Section 36.2 requires the head of a public body to develop a privacy management program in accordance with the minister's directions. A PIA process is a component of that program; so are the designated privacy officer, training, the breach process and the policies that document all of it. A public body that can produce its PIAs but not the program around them has answered half the question.

Breach notification. Section 36.3 defines a privacy breach as the theft or loss, or the unauthorized collection, use or disclosure, of personal information in a public body's custody or control. Where a breach could reasonably be expected to result in significant harm — identity theft, or significant bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, a negative impact on a credit record, or damage to or loss of property — the head must, without unreasonable delay, notify the affected individual and the Commissioner, with narrow exceptions where notification would itself cause grave harm. The PIA's risk section and the breach procedure should use the same list.

Ministries and other public bodies: the differences that matter

ElementMinistriesOther public bodies
Duty to conducts. 69(5), per the minister's directionss. 69(5.3), per the minister's directions
SubmissionTo the minister responsible, during development, for review and comment (s. 69(5.1))No general submission; the Commissioner is notified for common or integrated programs (s. 69(5.4))
Commissioner's reviewVia the minister, for common or integrated programs, on request (s. 69(5.2))Directly, for common or integrated programs, on request (s. 69(5.4))
Public recordSummaries in the personal information directory (s. 69(3)(c))A directory of personal information banks available for inspection (s. 69(6))
ProgramPrivacy management program under s. 36.2 and breach notification under s. 36.3 apply to all public bodies

Building the program

  1. Inventory initiatives, not systems. The directions attach to enactments, systems, projects, programs and activities. List them with owners, and mark which have a PIA on file.
  2. Define significant change for your organization. The directions give one example, a change of storage location outside Canada; your written threshold should add new categories of personal information, new uses or disclosures, new vendors and new automated decisions.
  3. Use the provincial template and keep the initiative-update form beside it. Most BC public bodies build on the government's standard PIA; a lighter update form keeps significant-change assessments proportionate.
  4. Delegate program sections to the program and keep the Part 3 analysis with the privacy office.
  5. Register the risks and the commitments with owners and dates, so the next assessment on the same initiative starts from history.
  6. Route common or integrated programs to the Commissioner notification in time: during development, not at launch.
  7. Document the program itself: the privacy officer, the training record, the breach procedure written to section 36.3, and the PIA process, so section 36.2 has an answer.

How AccessPoint runs it

AccessPoint's British Columbia jurisdiction pack carries the province's standard PIA template and a separate initiative-update template for significant changes, both versioned and pack-maintained, with FOIPPA attached as the governing legal authority.

Screener for the trigger

A preliminary screener captures whether an initiative is new, whether a PIA exists, and whether a change is significant under your written threshold, and stores the determination.

Typed questions that populate the register

The personal-information inventory as a table, a flow diagram question, and answers that bind retention, categories of personal data and the international-transfer flag to the subject's record of processing on approval — the offshoring supplement has a field to land in.

Section delegation

to the initiative's own people, with autosave, hours and documents, and coordinator approval.

Risks, controls and commitments

: a likelihood-and-impact register with a harm-to-individuals determination using section 36.3's harm list, controls from the controls library, and undertakings tracked to completion.

Review, freeze and re-assess

A configurable review carries the head's approval; approved assessments are read-only and the significant-change trigger goes forward through Re-assess on the same subject, with the reassessment date pulled forward when a subject's purpose changes.

Compliance profile

Each subject shows the pack's requirements: a required assessment reads as met while one is In Effect, and before-production items stay visible until the initiative is deployed.

The minister's and the Commissioner's copy

The closure tab generates the regulator summary as a document, and the assessment's documents, approvals and activity trail export together.

Breach response beside it

, with a risk-of-harm register and a notification checklist computed from the governing legislation.

Everything runs in your own Microsoft 365 and Azure tenant, in Canada, beside the FOIPPA access requests the same office handles.

A readiness checklist

  • Confirm which directions apply: ministries under section 69(5), other public bodies under section 69(5.3).
  • Inventory initiatives and mark which have a PIA on file.
  • Adopt the standard template and an initiative-update form.
  • Write a significant-change threshold and put it in a screener.
  • Confirm the one-year retention rule for decision-making information is checked in every PIA.
  • Add the offshoring supplement to any initiative storing personal information outside Canada.
  • Document the privacy management program under section 36.2.
  • Write the breach procedure to section 36.3's definition and harm list.

Sources

Related reading on this site: AccessPoint for British Columbia public bodies, privacy impact assessment software, the companion guides on Alberta's POPA PIAs, Ontario's mandatory PIAs and federal PIAs under the 2024 standard, or book a demo.

BC PIA Questions

Are privacy impact assessments mandatory in British Columbia?

Yes, for every public body. Section 69(5) of the Freedom of Information and Protection of Privacy Act requires the head of a ministry to conduct a privacy impact assessment in accordance with the directions of the minister responsible for the Act, and section 69(5.3) imposes the same duty on the head of every public body that is not a ministry. The current directions took effect on November 26, 2021.

When must a BC public body conduct a PIA?

Under the ministerial directions, on a new initiative for which no PIA has previously been conducted, and before implementing a significant change to an existing initiative, including a change to where sensitive personal information is stored when it is stored outside Canada. An initiative means an enactment, system, project, program or activity.

Does the PIA have to go to the minister or the Commissioner?

A ministry must submit the PIA for a proposed initiative to the minister responsible for the Act, during development, for review and comment. For a common or integrated program or activity, the Commissioner must be notified during development and, on request, given the PIA for review and comment; that duty applies to ministries through the minister and to other public bodies directly.

What is a BC privacy management program?

Section 36.2 of FOIPPA requires the head of every public body to develop a privacy management program in accordance with the minister's directions. The PIA process is one of its components, alongside the designated privacy officer, training, breach response and the policies that make the program real.

What are the breach notification rules in BC?

Section 36.3 requires the head of a public body, without unreasonable delay, to notify an affected individual and the Commissioner when a privacy breach could reasonably be expected to result in significant harm, including identity theft or significant bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, a negative impact on a credit record, or damage to or loss of property.

See AccessPoint in action. 30 minutes, on your jurisdiction's rules, with the person who built it.

© 2026 Realizer Services Inc. About Privacy Terms