Mist over a British Columbia forest and mountain ridge, evoking the province whose PIPA governs a therapist's client email

Email encryption for BC therapists under PIPA

Gabriel Borges14 min read

Search the full text of British Columbia’s Personal Information Protection Act for the word “encryption” and you get nothing. Not a weak reference, not a buried one. Zero occurrences, across the whole statute, in the consolidation current to August 4, 2026.

That’s the first thing worth knowing about email encryption in BC, because a lot of what gets written about it starts from the opposite assumption.

BC PIPA gives you one sentence of security obligation and leaves the method entirely to you. Encryption is how that obligation gets met for email in practice. It just isn’t what the Act asks for, and the difference matters when someone asks you to justify your setup.

This piece stays on the narrow question: what the safeguards duty means for encrypted email in BC, where BC genuinely differs from Ontario and Alberta, and what to set up. For the wider set of PIPA obligations, including consent mechanics and notification of collection, start with BC PIPA and therapist email. For the encryption options themselves, the comparison of PHIPA compliant email service options works through what’s actually available to a Canadian therapist.

The one sentence that governs your email

BC PIPA s.34 reads in full:

An organization must protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks.

That’s the whole security section. No protocol, no key length, no list of approved products, no mention of email at all.

The calibration comes from s.4(1), which rarely gets quoted alongside it: “In meeting its responsibilities under this Act, an organization must consider what a reasonable person would consider appropriate in the circumstances.” Reasonableness is assessed against the circumstances, and for a therapy practice the circumstances are set by what’s in the message.

An appointment reminder with a first name is a different risk from an assessment summary. Both travel on the same wire.

You’re an organization, not a custodian

Ontario and Alberta built health specific statutes around “custodians.” BC didn’t. BC PIPA s.1 defines “organization” to include a person, and excludes only individuals acting in a personal or domestic capacity, public bodies, and a short list of others.

A solo private practice in BC is an organization under a general private sector law. The same statute that governs a retailer’s customer list governs your clinical correspondence, which is why so much BC guidance reads as though it was written for someone else.

Why BC breach rules work differently

BC PIPA contains no breach notification duty. Not a narrow one, not a threshold based one. There is no section in the Act requiring you to tell anyone that a breach happened.

Almost every explainer that says otherwise has imported the wrong statute. BC’s mandatory regime lives in the Freedom of Information and Protection of Privacy Act at s.36.3, and FIPPA covers public bodies. If you’re in private practice, that section isn’t yours.

What replaces it is a recommendation. The Office of the Information and Privacy Commissioner for BC recommends notifying where a breach creates a real risk of significant harm. Voluntary and recommended is not the same as nothing, and it’s not the same as mandatory either.

Why BC breach rules work differently
JurisdictionNotification requiredThresholdBasis
BC, private practiceNo, voluntary and OIPC recommendedReal risk of significant harmBC PIPA s.34 safeguards only
BC, public bodiesYesStatutoryFIPPA s.36.3
OntarioYesAny unauthorized use or disclosurePHIPA s.12
Alberta, private practiceYesReal risk of significant harmAlberta PIPA s.34.1
Federal, PIPEDAYesReal risk of significant harmPIPEDA

Timing rules differ too, and the full side by side sits in the PHIPA vs HIA vs BC PIPA guide.

You still keep a record

Here’s the part most BC explainers skip. No duty to notify doesn’t mean no duty to document. The expectation to keep a record of the incident survives, and it’s the one that actually bites.

Think about how s.34 gets tested. Nobody assesses “reasonable security arrangements” on a quiet Tuesday. It gets assessed after something has gone wrong, by someone reading backwards from the incident.

A dated record of what happened, what you assessed, what you changed, and when is the evidence that your arrangements were reasonable. An assertion isn’t.

Where the fine ceiling actually sits

BC PIPA s.56(2) sets fines at not more than $10,000 for an individual and not more than $100,000 for a person other than an individual. Alberta’s PIPA s.59(2) sets exactly the same two numbers. Ontario is the outlier: PHIPA s.72(2) reaches $200,000 for an individual, with imprisonment up to a year, and $1,000,000 for an organization.

Two provinces at one ceiling and one at ten times it isn’t a ranking of how seriously each treats the duty. BC’s s.34 obligation is identical in kind to what Alberta and Ontario ask, and the OIPC’s order making power operates whether or not a fine is ever on the table. Until psychotherapy becomes a regulated title in BC in 2027, there’s also no college on the other side of it for most private practitioners, which puts more weight on the privacy regulator, not less.

What BC doesn’t require that Ontario does

This is where BC therapists get caught out by Ontario written guidance. Four things that are settled expectations in Ontario have no BC equivalent, and one thing everyone assumes differs doesn’t.

What BC doesn’t require that Ontario does
RequirementBCOntario
Audit trail of access and disclosureNot requiredExpected, driven by College of Registered Psychotherapists of Ontario (CRPO) Standard 5.6
Implied consent within a circle of careNo such mechanismYes, PHIPA s.20(2)
Lock box, client directed restriction on sharingNo mechanismYes
Written form for express consent to health dataNot required, electronic consent is validAlso not required in writing (s.18); express rather than implied for disclosure to a non custodian (s.18(3))
Data residency mandateNoneNone

Consent still exists in BC. Express consent is required for health information, and consent is granted per purpose, so clinical correspondence and appointment reminders are separate agreements. Feeding that information through an AI tool is another use, so it needs consent on the same footing. What BC doesn’t do is dictate the form that consent takes.

Worth saying plainly, since it cuts against our own product: BC PIPA does not require you to keep an audit trail of email. If someone tells you it does, they’re describing Ontario. Your college obligations may be a different matter, which is what the CRPO, CAP and CHCPBC email requirements comparison covers.

Where your email actually gets tested

Access requests. This is the mechanic BC guidance almost never connects to email, and it’s the one most likely to reach you before any regulator does.

Under BC PIPA s.23(1), a client can ask you for three things:

  • Their personal information under your control
  • Information about the ways you’ve used it
  • The names of the individuals and organizations you disclosed it to

Your sent folder is squarely inside all three.

The clock is s.29(1)(a), thirty days from receiving the request, extendable by up to thirty more under s.31(1) and beyond that only with the Commissioner’s permission. Then read s.1, which defines “day” as not including a holiday or a Saturday. Those are working days. Thirty of them is roughly six calendar weeks.

That timeline is generous right up until you try to produce the messages. If your encryption puts client correspondence into a portal you can’t search or export, the clock keeps running while you work out how to get it back.

Retention is a live obligation too

BC PIPA s.35 pulls in both directions and most people only know one half of it.

Section 35(1) sets a floor: where you used someone’s personal information to make a decision that directly affects them, you must keep it for at least one year afterwards, so they have a reasonable opportunity to get access to it. Section 35(2) sets a ceiling: destroy the documents, or strip the identifiers, once the collecting purpose is no longer served and retention is no longer needed for legal or business purposes.

BC PIPA sets no general minimum retention period beyond that one year rule. College obligations can sit on top, and for registered psychologists the College of Psychologists of British Columbia (CPBC) Code of Conduct 13.1 sets seven years from the end of service. If you’re a counsellor who isn’t registered with a BC college, that rule isn’t yours yet, and s.35 is what governs.

How to set up therapist email under BC PIPA

Seven steps. None of them require a product, and the first two matter more than the technical ones.

  1. List what actually leaves your practice by email. Appointment times, invoices, intake links, assessment summaries, referral letters, insurance forms. You can’t calibrate a safeguard to the circumstances until you know what’s moving.
  2. Take express consent for email, and record the date. BC doesn’t require it in writing and electronic consent is valid, so the constraint is your own record keeping, not the statute. Consent is per purpose: reminders and clinical correspondence are separate conversations.
  3. Make encryption automatic rather than a decision. Anything that depends on remembering to switch it on will eventually be off. Set transport encryption to be enforced rather than opportunistic, and define what happens when a receiving server won’t accept it.
  4. Name the individual responsible and publish the contact. s.4(3) requires you to designate one or more individuals responsible for compliance, and s.4(5) requires the position title and contact information to be public. In a solo practice that’s you, on your privacy notice.
  5. Decide where message content is stored, and be able to say it. BC sets no residency mandate. It does expect the decision to have been made deliberately and described accurately, and Canadian hosting carries a strong market expectation in BC even without a legal one.
  6. Write a breach procedure whose first step is keeping a record. Who assesses the risk, what gets written down, where the record lives. Then the notification question, which is a judgment call about real risk of significant harm rather than a statutory trigger.
  7. Set a retention and destruction rule for email. Apply it to the mailbox and to any portal holding encrypted messages, not only to the clinical record.

Step three is where most practices stall, because opportunistic transport encryption looks like encryption right up to the moment the receiving server declines it and the message goes anyway.

Curio encrypts every outbound message from your existing Gmail for Canadian mental health privacy law, with no migration and no second inbox, and logs every send in a Canadian audit trail. BC doesn’t require that audit trail. What it gives you is a dated answer to the question s.34 gets assessed on. Curio’s compliance infrastructure, including that audit trail and any encrypted portal messages, runs on GCP northamerica-northeast1 in Montreal.

Join the waitlist.

What changes on November 29, 2027

Psychotherapy becomes a regulated title in British Columbia on November 29, 2027, under a designation regulation made pursuant to the Health Professions and Occupations Act, S.B.C. 2022, c. 43. The regulator is the College of Health and Care Professionals of BC.

What changes for email isn’t PIPA. PIPA already applies and its wording doesn’t move. What arrives is a second layer: a college with practice standards, a complaints process, an expectation about how records are kept, and its own view of what electronic communication should look like. Ontario therapists have operated with both layers for years, which is exactly why Ontario guidance reads as stricter.

What those standards will say about email is not something we can tell you, and neither can anyone else, because they aren’t published yet. The detail on the regulation itself, the timeline and the registration path is in the CHCPBC psychotherapy regulation guide, and the title protection consequences are worked through in what protected title changes for your email.

The practical point is narrow. Everything in the seven steps above is a PIPA obligation or a documentation habit. None of it becomes wrong when a college standard arrives on top of it.

What this doesn’t fix

Encryption isn’t consent. A message can be encrypted end to end and still be a disclosure the client never agreed to. The consent conversation is separate work and the statute treats it separately.

Encryption also isn’t compliance. BC PIPA reaches collection, use, disclosure, accuracy, access, correction, retention and destruction. Email safeguards are one clause of one section.

And no product makes you compliant, including ours. What a good setup does is stop email from being the part of your practice you have to think about.

If you’re unsure whether something you’ve already sent crossed a line, take it to a privacy lawyer. The OIPC also publishes guidance for organizations, which is worth reading before you decide you have a problem.

What you can do today, without advice, is close the gap going forward and write down the date you closed it.

Common questions

Does BC PIPA require encrypted email?

No. The words “encrypt,” “encryption” and “encrypted” appear zero times in the Act. s.34 requires reasonable security arrangements to prevent unauthorized access, and s.4(1) measures reasonableness against what a reasonable person would consider appropriate in the circumstances. For therapy content sent by email, encryption is the practical way to meet that duty.

Do I have to report a privacy breach in BC?

Not under BC PIPA, if you’re in private practice. There is no notification duty in the Act. The OIPC recommends notifying affected individuals where a breach creates a real risk of significant harm, and the expectation to keep a record of the incident stands regardless. BC’s mandatory regime, FIPPA s.36.3, applies to public bodies.

Not in writing, no. BC requires express consent for health information but doesn’t dictate the form it takes, and electronic consent is valid. Ontario doesn’t require writing either, though PHIPA s.18(3) requires express rather than implied consent for disclosure to someone outside the circle of care. Record the date you took consent anyway, because that’s what you’ll be asked to produce.

Do I need an audit trail of client emails in BC?

BC PIPA doesn’t require one. Ontario’s expectation comes from CRPO Standard 5.6, a college standard rather than the statute. A record is still the practical way to answer an access request under s.23 or to show what your safeguards did on a given date, since s.34 gets assessed after the fact.

Does client data have to stay in Canada under BC PIPA?

No. BC PIPA sets no data residency mandate and permits cross border transfer. The residency rules people remember are FIPPA’s, and those bind public bodies. Canadian hosting carries a strong market expectation in BC, and where content sits is one input into whether your arrangements are reasonable under s.34.


Product disclaimer: Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.

Regulatory content disclaimer: This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook