A background check feels like a purchase. You pick a package, you pay a fee, a report arrives, and you make a decision. That framing is the problem. What you actually did was collect personal information about an identifiable individual, for a stated purpose, using a third party, and then take custody of the result. In British Columbia that is a regulated activity with a statute attached, and the statute has opinions about all four of those steps.

This article has two halves: consent, and the categories of information that no firm can lawfully obtain for you whatever it charges. That second list is a diagnostic. A vendor's offering, read against it, tells you how the vendor operates.

Part one: consent

The Act that applies

Information about an identifiable individual, held by a private-sector organization in BC, is governed by the Personal Information Protection Act. A background check is squarely within it. So is the report when it lands in your inbox, and so is the copy your vendor keeps.

The default position under the Act is consent. There is a separate route for employee personal information — the Act permits an organization to collect (s.13), use (s.16) and disclose (s.19) employee personal information without consent where it is reasonable for the purposes of establishing, managing or terminating an employment relationship, and each of those sections carries a duty to notify the individual that the collection is happening and why. That route is narrower than it is usually treated. It is tied to an employment relationship, and it is a duty-bearing route rather than a free pass: the notification is the price of not seeking consent.

Whether a job applicant who has not yet been hired sits inside that route is exactly the question worth putting to your own counsel rather than to a vendor's sales page. We are not going to resolve it for you here, and a confident one-line answer from anybody selling checks should make you more careful rather than less. The practical version: specific, informed, written consent from the candidate is the route that does not depend on winning that argument. It costs one page and one signature.

What "informed" is doing in that sentence

Consent under a purpose-based statute is not a signature on a blank cheque. It attaches to a purpose. The consent form that reads "I authorize the company and its agents to obtain any and all information about me from any source" is asking to do work that no consent can do — it names no purpose, no category and no source, and a person cannot meaningfully agree to a scope that has not been described to them.

The version that survives scrutiny is boring and specific. It names what will be collected — criminal record check, employment verification, education verification, licence status, references. It names why, in terms of the actual role. It names who is doing the collecting, if that is a third-party firm. And where a category has its own separate legal regime, it carries its own separate authorization rather than being smuggled in under a general clause.

There is also a sequencing point that catches employers repeatedly: the consent has to exist before the collection, not after. A check run on Monday and papered on Friday was still run on Monday.

The part everyone forgets: the report is now your record

When the report arrives, you have not finished a transaction — you have acquired personal information. Section 34 requires an organization to protect personal information in its custody or under its control by making reasonable security arrangements against unauthorized access, collection, use, disclosure, copying, modification or disposal. A background report sitting in a shared drive, a recruiting inbox, or a hiring manager's laptop is the thing that section is describing.

Section 35 then cuts both ways at once. Where information was used to make a decision that directly affects an individual, it must be kept for at least a year so the person has a reasonable opportunity to obtain access to it. And documents containing personal information must be destroyed, or stripped of the means of associating them with individuals, once the purpose is no longer served and retention is no longer needed for legal or business reasons. So the report on the candidate you hired and the report on the four you did not are governed by the same section and probably need different answers.

That is the same obligation attached to your access control system, which we wrote about in your door logs are personal information. Different system, identical duty.

Part two: what nobody can lawfully get you

Below is what falls outside any lawful background check in this province, no matter who is selling it. A firm that offers you an item on this list is not demonstrating capability. It is telling you how it operates, and you are the one who ends up holding the collection.

Records that have been sealed or made non-disclosable. Certain records are, by law, not available to be handed to an employer — records subject to a suspension, records governed by the separate federal regime for young persons, and outcomes that were never convictions at all. We are deliberately not citing section numbers for those regimes, because we have not verified them against the primary source, and this site does not print clause numbers it has not read. The operative point does not need one: a criminal record check is a defined product with a defined output, produced by the agency that holds the records, on that agency's terms, with the candidate's own participation. Anything richer than that defined output did not come from the defined process. "The full file" is not a premium tier.

Credit information, without the consent its own regime requires. Credit reporting in BC has its own statutory home — Part 6 of the Business Practices and Consumer Protection Act — separate from the privacy statute above and separate from your general employment consent form. We are citing no provision of it here, and no responsible vendor should be paraphrasing its terms at you either. The practical rule is simply this: a credit check is its own decision, needing its own specific authorization and its own justification tied to the role, and a general "any and all information" clause does not reach it. If a package quietly includes credit information under a bundled consent, the bundling is the defect.

Banking records. There is no lawful commercial channel by which a private firm obtains an individual's bank records for a hiring decision. None. Where such records surface, they were obtained by someone impersonating a person or an account holder, or by access to a system or an account that was not authorized — territory covered by Criminal Code s.403 on identity fraud and s.342.1 on unauthorized use of a computer. This is the clearest test on the list — there is no ambiguous version of it.

Health information. A person's medical history, prescriptions, diagnoses or treatment are not background-check material. Where a role genuinely has a medical or physical requirement, that is handled as its own process, with its own consent, usually through a qualified practitioner, and it produces a fitness answer rather than a file of records. A vendor offering health information as an add-on is offering either a breach of somebody else's custody obligation or a pretext, and you would be the party who commissioned it.

Anything obtained by pretext. Pretexting is obtaining information by pretending to be someone you are not. It is unlawful, we do not do it, and we are not going to describe how it is done. The relevant sections are the ones above — s.403 where a real, identifiable person is impersonated to gain an advantage, and s.342.1 where an account or system is entered. Add Criminal Code s.184, which makes it an offence to knowingly intercept a private communication by means of an electro-magnetic, acoustic, mechanical or other device; s.184(2) sets out the exceptions, and the only one available to a private party is the consent of a participant in the conversation.

The closed databases. No private firm can query CPIC, and none has a lawful route into the record systems of any enforcement agency. There is no professional-courtesy channel and no category of licence that opens one. The Security Services Regulation allows the registrar to impose a code of conduct as a condition of a licence, including a requirement to act with honesty and integrity (s.14) — which is the provision an implied claim of closed-system access runs directly into. We set out the full version of these limits, with sections you can open and read, in what a BC private investigator can and cannot legally do.

Covert collection dressed up as verification. Following a candidate, sitting on their home, or placing a device on a vehicle is not background screening. BC's Privacy Act makes it a tort, actionable without proof of damage, for a person wilfully and without a claim of right to violate the privacy of another (s.1(1)); privacy may be violated by surveillance whether or not there is any trespass (s.1(4)); the standard is the privacy reasonable in the circumstances (s.1(2)); and s.2 sets out the exceptions. A hiring decision is not one of them.

How to read a background-check offering

You do not need to be a lawyer to audit a vendor's page. Four questions do most of the work.

"What is the source of each item?" Every line on a lawful report traces to a source you can name: a court registry, a corporate registry, a licence register, a former employer who was contacted, an institution that confirmed a credential, the defined record-check product. A vendor who answers with a capability ("our database", "our network", "our contacts") rather than a source has told you the thing that matters. Ask again for a source, once. The second answer is the real one.

"Which items need their own consent, and do you supply that form?" A vendor that has thought about consent will separate the categories that need separate authorization and will hand you the paperwork. A vendor that has not will tell you one signature covers everything, which is the answer that puts the exposure on you rather than on them.

"What does the turnaround time imply?" Real verification involves other parties with their own processes and hours. An instant, nationwide, everything-included result is describing an aggregation of unverified data, a closed system nobody has, or both. Speed is not a red flag on its own; speed inconsistent with the named sources is.

"What happens to my file afterwards?" Retention, storage, who at the vendor can see it, and when it is destroyed. Section 34 and section 35 apply to the vendor's copy as much as yours, and a firm that cannot answer this has not read the Act it is operating under.

One more, worth asking anybody in this industry: is the firm licensed under the Security Services Act, and what is the licence number? Seeking or obtaining information about the activities, character or repute of a person, for consideration, is what the Act defines a private investigator as doing (s.1). That makes a great deal of background work licensed work, regardless of what the service is called on the website. Ours is published in the footer of every page on this site, which is why we are comfortable telling you to ask.

The uncomfortable summary

The lawful background check is narrower than the marketed one, and that is the whole finding. It is consent-based, purpose-limited, sourced from records that will name their origin, and it leaves you holding a file with an obligation attached. It will not tell you everything about a person. It was never able to.

The offerings that promise more are not competing on quality. They are describing collections that are unlawful, non-existent, or both — and in a hiring dispute, the party who commissioned the collection is standing next to the party who performed it. If a proposal in front of you contains one of the items in part two, you now have the specific reason to decline it.

If you want a background check run properly on a candidate in British Columbia, the conversation starts with the decision you are trying to make and works backwards to what may lawfully be collected to support it. Contact us and we will tell you plainly what falls inside that and what does not.

Sources

  • Personal Information Protection Act, SBC 2003, c. 63, s.13 (collection of employee personal information), s.16 (use), s.19 (disclosure), s.34 (protection of personal information), s.35 (retention and destruction) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Privacy Act, RSBC 1996, c. 373, s.1(1) (violation of privacy actionable without proof of damage), s.1(2) (privacy reasonable in the circumstances), s.1(4) (surveillance, with or without trespass), s.2 (exceptions) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/96373_01
  • Criminal Code, RSC 1985, c. C-46, s.184 (interception of private communications) and s.184(2) (exceptions, including participant consent) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-184.html
  • Criminal Code, s.342.1 (unauthorized use of a computer) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.html
  • Criminal Code, s.403 (identity fraud) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-403.html
  • Security Services Act, SBC 2007, c. 30, s.1 (definitions of "security work" and "private investigator") — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/07030_01
  • Security Services Regulation, BC Reg 207/2008, s.14 (code of conduct as a licence condition) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/207_2008
  • Business Practices and Consumer Protection Act, SBC 2004, c. 2 — Part 6 is the credit reporting regime. No provision of it is cited or quoted in this article; the general reference is given so a reader can find the Act — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/04002_09