BC Realtor PIPA Privacy Guide (2026): Personal Information Protection Act Compliance
Most BC realtors are vaguely aware they have "privacy obligations" but could not name the actual statute. In BC, it's PIPA — the Personal Information Protection Act — not federal PIPEDA. PIPA governs how you collect, use, store, and disclose every piece of client information in your practice. Non-compliance isn't theoretical: the BC Office of the Information and Privacy Commissioner (OIPC) investigates complaints, and BCFSA treats privacy failures as professional conduct issues. This guide gives you a practical, plain-language compliance framework for your real estate business.
PIPA vs. PIPEDA: Which Law Applies to BC Realtors?
Canada has a dual privacy law framework for private-sector organizations:
- Federal PIPEDA (Personal Information Protection and Electronic Documents Act) — applies to organizations engaged in commercial activity that collect, use, or disclose personal information in the course of interprovincial or international transactions.
- BC PIPA (Personal Information Protection Act, SBC 2003, c. 63) — applies to private-sector organizations operating entirely within BC. PIPA was declared "substantially similar" to PIPEDA by the federal government, so it takes precedence for intra-provincial BC businesses.
For the vast majority of BC real estate transactions — which involve buyers, sellers, and properties all within BC — PIPA is the governing law. PIPEDA comes into play primarily for:
- Relocation clients moving from another province into BC (or vice versa)
- Out-of-province mortgage lenders and other federally-regulated entities involved in the transaction
- Any internet-based commercial activity crossing borders
The practical compliance requirements under PIPA and PIPEDA are largely similar. The key regulator for BC realtors is the BC Information and Privacy Commissioner (OIPC BC) for PIPA matters.
PIPA in transition — what's coming:
BC's PIPA is currently under review. Proposed amendments (Bill 38, 2021 — not yet in force as of 2026) would substantially strengthen individual rights, expand breach notification requirements, and increase fines. Realtors should monitor OIPC and BCREA communications for updates on PIPA modernization. The core compliance requirements discussed in this guide reflect PIPA as currently in force.
What Counts as Personal Information Under PIPA?
PIPA defines personal information broadly as "information about an identifiable individual." In real estate practice, this includes virtually everything you collect about clients:
| Information Type | Examples in Real Estate Context | Sensitivity Level |
|---|---|---|
| Contact information | Name, address, phone, email | Lower |
| Financial information | Income, bank details, mortgage qualification, credit score, purchase price limits | High |
| Government IDs | Driver's licence, passport details (for FINTRAC identity verification) | High |
| Property information | Current home ownership, property values, mortgage amounts | Medium |
| Family situation | Marital status, divorce proceeding, children, family composition | Medium |
| Transaction preferences | Motivation for sale, pricing bottom line, negotiating flexibility | Medium |
| Health information | Accessibility needs, health condition (if relevant to property requirements) | High |
| Communication records | Email exchanges, text messages, call notes in CRM | Medium |
| Photos | Client photos for marketing (with consent), property photos showing personal items | Medium |
Notably, business contact information (a person's business title, business phone, business address) is generally excluded from PIPA when collected solely for business communication purposes. Personal contact information that happens to be used for business (personal cell phone, home email) is still covered.
PIPA's 10 Fair Information Principles for Realtors
PIPA is built around 10 fair information principles. Understanding each in a real estate context is the foundation of compliance:
1. Accountability
You are responsible for personal information you collect — including information transferred to third parties (mortgage brokers, lawyers, inspectors) for purposes you control. You must designate a privacy officer (typically yourself, or a named individual at a brokerage).
In practice: Have a written privacy policy. Know who at your brokerage handles privacy complaints. Document your information handling practices.
2. Identifying Purposes
You must identify the purpose for collecting personal information before or at the time of collection. In real estate, this typically means explaining to clients why you're collecting their financial details, government ID, and contact information.
In practice: Have a client intake form or disclosure that states: "We collect your personal information to provide real estate services, comply with FINTRAC requirements, and communicate about the transaction."
3. Consent
Collection, use, and disclosure of personal information requires consent. Consent can be:
- Express consent — explicit, written or verbal agreement (required for sensitive information or secondary uses)
- Implied consent — reasonably inferred from the context (generally sufficient for collecting information necessary to complete the transaction)
The key consent questions for realtors are about secondary uses: Can you use client information to add them to a marketing list? Send them property alerts after the transaction closes? Refer them to a mortgage broker? These secondary uses require separate, explicit consent.
4. Limiting Collection
Collect only what you need for identified purposes. Don't collect information "just in case." If you don't need a client's SIN number for the real estate transaction (you generally don't), don't collect it.
5. Limiting Use, Disclosure, and Retention
Use personal information only for the purpose it was collected. Retain it only as long as necessary. After the retention period, destroy it securely.
In practice: Client files from closed transactions should be reviewed and purged (beyond what BCFSA requires to retain) once the retention period passes.
6. Accuracy
Keep personal information accurate, complete, and up-to-date. If a client updates their contact information, update your records. Don't rely on outdated financial details when advising on affordability.
7. Safeguards
Use appropriate security measures to protect personal information against unauthorized access, disclosure, copying, use, or disposal. The level of safeguards must match the sensitivity of the information.
In practice: Lock file cabinets. Use password managers and two-factor authentication on CRM and email accounts. Encrypt files containing government IDs or financial information before emailing. Use a reputable, Canadian-hosted CRM.
8. Openness
Your privacy practices must be publicly available. This means having a privacy policy on your website and being prepared to explain your information practices to clients who ask.
9. Individual Access
Clients have a right to access their own personal information you hold, to know how it's being used, and to challenge its accuracy. You must respond to access requests within 30 days (with limited extensions).
In practice: Have a process for handling access requests. Know where all client information is stored so you can compile a response.
10. Challenging Compliance
Clients can challenge your compliance with PIPA and file a complaint with the OIPC if they believe you've mishandled their information. You must have a process for addressing complaints.
Consent in Real Estate: When You Need It and What Form
| Use of Information | Consent Type Required | Notes |
|---|---|---|
| Collecting contact and financial info for the transaction | Implied | Purpose is obvious; must still inform client |
| FINTRAC identity verification (government IDs) | Implied + FINTRAC duty | Legally required to collect; client must be informed |
| Sharing with cooperating realtor on the other side | Implied | Sharing information necessary for the transaction is implied |
| Sharing with notary/lawyer, inspector, mortgage broker | Implied | Service providers working on the same transaction |
| Adding to a marketing list / newsletter | Express — CASL required | Separate consent; must explain they can unsubscribe |
| Sending property alerts after transaction closes | Express | No longer working for client; secondary use requires new consent |
| Referring client to mortgage broker, insurance agent | Express | Sharing with third party for commercial purpose outside the transaction |
| Using client's name/photo in a testimonial or case study | Express — written | Marketing use; always get written sign-off |
| Sharing transaction information with your brokerage for supervision | Implied | Required for BCFSA oversight; client should be informed |
PIPA and CASL: How They Overlap
Canada's Anti-Spam Legislation (CASL) adds a parallel layer of consent obligations for electronic commercial messages (email, text, some social media). CASL and PIPA overlap significantly for realtors:
- PIPA governs: collection, use, and storage of personal information generally
- CASL governs: sending commercial electronic messages specifically — requires express or implied consent to contact, an identification of sender, and an unsubscribe mechanism
For realtor marketing purposes, CASL's requirements are typically stricter and more practically relevant. A compliant CASL consent process (express written consent to receive marketing emails) will generally satisfy PIPA's requirements for that secondary use as well.
CASL's "implied consent" window is particularly useful for realtors: an existing business relationship (e.g., a client you just completed a transaction with) creates implied consent to send commercial electronic messages for 2 years after the transaction closes. After that, you need express consent to continue marketing.
Building a PIPA-Compliant Privacy Program for Your Practice
Step 1 — Privacy Policy
Create a one-page written privacy policy for your practice that covers:
- What information you collect and why
- How you use and share it (transaction services, FINTRAC, brokerages, service providers)
- How long you retain it (BCFSA's 7-year minimum + your destruction policy)
- How clients can access or correct their information
- How to lodge a privacy complaint with you or the OIPC
- Your contact information as the privacy officer
This policy should be on your website and available to clients on request.
Step 2 — Client Intake Disclosure
At the start of every client relationship, provide a brief disclosure (can be part of your representation agreement or a separate one-pager) that informs clients:
- What information you're collecting
- The purposes (providing real estate services, FINTRAC compliance)
- That certain information is legally required (FINTRAC ID)
- Any additional uses you want consent for (marketing, referrals)
Step 3 — Consent Capture for Secondary Uses
If you want to add clients to a newsletter, send market updates, or make referrals after the transaction, build a consent mechanism into your intake process:
- A checkbox on your intake form: "I agree to receive market updates and real estate newsletters from [Agent Name]. I can unsubscribe at any time."
- A separate consent form at closing for post-transaction marketing
- A CRM that tracks consent status and enforces unsubscribe requests
Step 4 — Safeguard Your Information
A practical safeguard checklist for realtors:
- Use strong, unique passwords for CRM, email, and cloud storage — use a password manager
- Enable two-factor authentication on all accounts containing client data
- Never email government IDs or financial documents without password protection or encryption
- Use a CRM with Canadian data residency (data stored in Canada, not US servers)
- Lock or password-protect your laptop and phone
- Shred paper documents containing personal information before disposal
- Review third-party service provider privacy practices (CRM vendors, email platforms, cloud storage)
Step 5 — Retention and Destruction Policy
BCFSA requires realtors to retain records for at least 7 years. After that minimum period, PIPA requires destruction once you no longer need the information. Establish a schedule:
- Transaction files: 7 years from close (BCFSA minimum), then secure destruction
- Marketing/CRM contacts: Until the person unsubscribes or requests deletion (or CASL implied consent expires — 2 years without express consent)
- FINTRAC records: 5 years from the date of the last transaction
- Unsuccessful leads (no transaction): Typically 1–2 years is sufficient, then destroy
Privacy Breach Protocol
A privacy breach is any incident where personal information is collected, used, or disclosed contrary to PIPA — including accidental breaches (lost laptop, email sent to wrong address).
What Triggers Reporting Obligations
Under PIPA, a breach triggers reporting obligations if it involves a "real risk of significant harm" to individuals. Significant harm includes:
- Identity theft or fraud
- Financial loss or harm
- Damage to reputation or relationships
- Physical harm or safety risks
- Humiliation or psychological harm
| Breach Type | Risk Assessment | Reporting Likely Required? |
|---|---|---|
| Email with contract sent to wrong address (another realtor) | Low — contains address and buyer name | Possibly not (assess context) |
| Email with government IDs sent to wrong recipient (stranger) | High — identity theft risk with passport/licence | Yes |
| Laptop lost with unencrypted client files | High — financial details, IDs potentially exposed | Yes |
| CRM hacked; client database accessed | High — broad exposure of client data | Yes |
| Client information discussed with unauthorized person (gossip) | Variable — depends on what was disclosed | Assess context |
4-Step Breach Response
- Contain: Immediately stop the breach. Retrieve the misdirected email, remotely wipe the lost device, isolate the compromised system.
- Assess: Determine what information was involved, who was affected, and whether there is a real risk of significant harm.
- Notify: If the risk of significant harm threshold is met, notify the affected individuals and report to the OIPC. Don't delay — notification should happen promptly.
- Document and remediate: Document what happened, what you did, and how you're preventing recurrence. Adjust your processes to close the gap that led to the breach.
What Happens When a Client Files an OIPC Complaint
The BC OIPC receives privacy complaints and investigates potential PIPA violations. If a client believes you have mishandled their information, they can file a complaint after first attempting to resolve it with you.
The OIPC investigation process:
- Complaint filed — OIPC reviews and decides whether to accept for investigation
- If accepted, OIPC notifies you and requests a response
- Mediation attempted — many complaints resolved at this stage
- If not resolved, OIPC investigates formally and issues findings
- Findings may include orders to stop practices, correct information, or comply with PIPA
Serious or repeated violations can result in fines under PIPA (up to $100,000 per organization for intentional violations). BCFSA may also take professional conduct action based on OIPC findings.
Practical PIPA Compliance Checklist for BC Realtors
| Item | Action Required | Status |
|---|---|---|
| Privacy Policy | Written policy on website and available to clients | Required |
| Privacy Officer Designation | Named person responsible (likely yourself) | Required |
| Client Intake Disclosure | Inform clients what you collect and why | Required |
| Marketing Consent Process | Express consent before adding to newsletter/marketing list | Required |
| Secure File Storage | Encrypted storage for government IDs and financials | Required |
| Access Credentials | 2FA on CRM, email, cloud storage; strong unique passwords | Required |
| Retention Schedule | 7-year minimum for transaction files; review and purge thereafter | Required |
| Breach Response Plan | Know what to do if a breach occurs | Required |
| Third-Party Vendor Review | Check CRM and email vendor privacy terms; prefer Canadian data residency | Best Practice |
| Annual Privacy Review | Review practices annually or when significant change occurs | Best Practice |
Frequently Asked Questions
Does PIPA or PIPEDA apply to BC realtors?
PIPA (BC's Personal Information Protection Act) is the primary privacy law for BC realtors operating entirely within BC. Because most BC real estate transactions are intra-provincial, PIPA is the governing law. PIPA has been recognized as substantially similar to PIPEDA by the federal government.
What personal information do BC realtors collect that is covered by PIPA?
Personal information under PIPA includes any information about an identifiable individual: names, phone numbers, email addresses, financial information (income, credit details), government IDs (for FINTRAC), property ownership history, negotiating preferences, family situation, health information, and any other details that could identify a specific person.
Do BC realtors need consent to collect client information?
Yes. PIPA requires meaningful consent before collecting, using, or disclosing personal information. For most real estate services, implied consent is sufficient when the purpose is obvious — but realtors must still inform clients of what information is being collected and why. For secondary uses (marketing, referrals, third-party sharing), express consent is required.
How long can BC realtors retain client personal information?
PIPA requires that personal information only be retained as long as necessary for the identified purposes. For real estate, BCFSA requires a minimum 7-year retention of transaction records. After that period, information should be securely destroyed unless there is another legal reason to retain it.
What happens if a BC realtor has a privacy breach?
Under PIPA, a breach must be reported to the BC Information and Privacy Commissioner (OIPC) if there is a real risk of significant harm to individuals. Affected individuals must also be notified. Failure to report can result in fines and BCFSA sanctions.
Privacy-Compliant Client Management
Magnate360 CRM is built with CASL consent tracking, secure Canadian data handling, and audit trails — compliance built into every interaction.