A new privacy law headline can create confusion for business owners. With British Columbia’s Bill 9, some organizations may wonder whether their data breach notification requirements have suddenly changed.
For private-sector businesses, the important distinction is which privacy law applies to your organization.
Bill 9, the Freedom of Information and Protection of Privacy Amendment Act, 2026, amends British Columbia’s Freedom of Information and Protection of Privacy Act, commonly known as FIPPA. FIPPA primarily governs public bodies and their handling of personal information. The legislation includes changes related to public-sector information access, connected services, and information sharing by the Information and Privacy Commissioner.
Private-sector businesses in British Columbia also need to consider the Personal Information Protection Act (PIPA), while organizations subject to federal PIPEDA have separate federal breach reporting and notification obligations.
For a Chilliwack accounting firm, dental practice, construction company, nonprofit, professional office, or other business handling personal information, the practical takeaway is simple: do not assume that news about Bill 9 replaces your existing privacy and data breach responsibilities.
What Is Bill 9 and Who Does It Apply To?
Bill 9 is the Freedom of Information and Protection of Privacy Amendment Act, 2026. It amends FIPPA, British Columbia’s public-sector privacy and access-to-information legislation. The legislation received Royal Assent in May 2026, with some provisions subject to specified commencement rules.
FIPPA applies to BC public bodies, including organizations such as provincial ministries, municipalities, school districts, and health authorities.
That is different from the privacy legislation that applies to many private-sector organizations.
For businesses, this distinction matters because a change to FIPPA should not automatically be treated as a change to the privacy requirements governing a private company.
If your organization collects customer information, employee information, patient information, financial information, or other personal data, you still need to understand the privacy laws that apply to your particular business and circumstances.
What Are the Data Breach Notification Requirements for BC Businesses?
For businesses subject to PIPEDA, federal breach reporting requirements are already established.
Under PIPEDA, an organization must report a breach of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada when it is reasonable to believe the breach creates a real risk of significant harm to an affected individual. The organization must also notify affected individuals and keep records of breaches.
The assessment is not based solely on whether information was technically exposed. PIPEDA requires organizations to consider factors including:
The sensitivity of the personal information involved
The probability that the information has been or will be misused
The circumstances surrounding the breach
The potential consequences for affected individuals
Significant harm can include financial loss, identity theft, damage to reputation or relationships, and other serious impacts.
This means businesses should have a documented process for assessing a suspected data breach rather than making decisions informally during an incident.
When Does a Business Need to Notify People About a Data Breach?
There is no universal rule that every security incident automatically requires public notification.
Under PIPEDA, the organization first needs to determine whether the breach creates a real risk of significant harm. If that threshold is met, the organization must report the breach to the Privacy Commissioner and notify affected individuals as required.
The timing matters too. The federal Privacy Commissioner states that notifications must be made as soon as feasible after the organization determines that the breach has occurred.
For example, losing a device containing no sensitive information may require a different assessment from an incident involving exposed banking information, medical records, government identification numbers, or credentials that could be used for identity theft.
The important step is to document the assessment and the reasoning behind the decision.
What Should a Data Breach Notification Include?
When notification is required under PIPEDA, the communication needs to provide affected individuals with enough information to understand the significance of the breach and take appropriate steps to reduce or mitigate potential harm.
Depending on the circumstances, a notification may need to explain:
What happened
When the incident occurred or was discovered
What type of personal information was involved
What the organization has done to contain the incident
What the organization is doing to prevent further harm
What affected individuals can do to protect themselves
How affected individuals can contact the organization for additional information
A vague message that simply says “your information may have been compromised” may not provide enough useful information.
Your incident response plan should therefore include a process for preparing and reviewing privacy breach notifications before they are needed.
Why Data Breach Preparation Matters for Fraser Valley Businesses
A cybersecurity incident is not only an IT problem.
A data breach can involve business owners, employees, customers, legal counsel, insurers, IT providers, privacy professionals, and potentially regulators.
For businesses in Chilliwack, Abbotsford, Mission, Langley, and throughout the Fraser Valley, having a documented process can make the response considerably more organized.
Consider a situation where an employee clicks a phishing link and an attacker gains access to a Microsoft 365 account. The business may need to determine:
What information did the attacker access?
How long did they have access?
Was personal information involved?
Was any information downloaded or misused?
Which customers or employees may be affected?
Does the incident meet the applicable reporting threshold?
Who makes that determination?
Who communicates with affected individuals?
What evidence needs to be preserved?
What security controls need to be strengthened?
Without a documented process, these questions may not be answered consistently.
Cyber Insurance and Data Breach Response
Privacy obligations are also relevant when reviewing your cyber insurance requirements.
Insurance applications and renewals may ask about cybersecurity controls, employee training, multi-factor authentication, backups, incident response procedures, and how the organization handles security incidents.
Your insurance policy may also specify notification or response procedures following a suspected cyber incident.
That is why businesses should understand their policy requirements before an incident happens. Keep emergency contact information accessible and know who is responsible for contacting the insurer, IT provider, and legal or privacy professionals.
How to Prepare for Data Breach Notification Requirements
You do not need a complicated compliance program to start improving your data breach readiness.
Begin with a written data breach response plan that identifies:
Who is responsible for leading the response
Who assesses whether personal information was affected
Who determines whether notification may be required
Who contacts your IT or cybersecurity provider
Who contacts your insurer
Who communicates with employees and customers
Where incident records are maintained
How evidence is preserved
How affected systems are secured and restored
Next, reduce the likelihood of a breach in the first place.
Investing in the right security tools for a small business environment can help strengthen protections around email, endpoints, accounts, networks, and business data.
Multi-factor authentication, employee awareness training, endpoint protection, secure backups, patch management, access controls, and email security can all form part of a broader cybersecurity strategy.
Keep Your Privacy Policy and Breach Process Current
Privacy policies and cybersecurity procedures should not be written once and forgotten.
Review them periodically and whenever your organization changes how it collects, stores, shares, or processes personal information.
It is also important to distinguish between general privacy information and the specific requirements that apply to your organization. The Office of the Privacy Commissioner of Canada’s PIPEDA guidance provides information about federal privacy requirements and breach obligations.
If your organization is subject to BC’s private-sector privacy legislation or another sector-specific requirement, you should also confirm the rules that apply to your particular situation.
Bill 9 Does Not Mean Businesses Can Ignore Existing Privacy Obligations
Bill 9 has generated attention around privacy and information management in British Columbia, but businesses should not interpret the legislation as a replacement for their existing private-sector privacy responsibilities.
For organizations subject to PIPEDA, mandatory breach reporting, notification, and breach record-keeping requirements are already established.
The practical response for a Fraser Valley business is not to wait for another legislative headline.
Know which privacy laws apply to your organization. Document your data breach notification requirements. Assign responsibility for breach assessments. Keep emergency contacts available. Test your incident response process. And make sure your cybersecurity controls are strong enough to reduce the likelihood of a breach in the first place.
Privacy compliance is much easier to manage when the process is established before an incident occurs.