Something has gone wrong. Stock is disappearing, an expense pattern does not add up, a complaint has landed on a manager's desk, or a supervisor has seen something they cannot unsee. Somebody says the sensible thing — let's look into it before we do anything — and the looking begins.
Within a day or two, the looking has produced a file. Door logs for a three-month window. Camera footage pulled from two positions. A manager's notes of a conversation with a colleague. An export of an email mailbox. A copy of a schedule marked up in red pen. Perhaps a memo from the person who raised it in the first place.
That file is not a neutral folder of facts. In British Columbia it is a collection of personal information about an identifiable individual, held by an organization, which puts it squarely inside the Personal Information Protection Act. And because the individual is an employee and the organization is their employer, it is inside a specific part of the Act with its own rules — rules that most employers have never read, and that are not difficult once someone points at them.
The uncomfortable part is not that the rules are strict. It is that getting the sequence wrong is what turns an investigation that supports a defensible decision into an investigation that becomes its own separate problem.
The question we ask at intake
Before anything is pulled, exported or reviewed, there is one question worth answering in writing:
What decision is this investigation meant to support?
Not "what happened" — that is what the investigation is for. The decision. A dismissal. A discipline step short of dismissal. An insurance claim. A change to a procedure that failed. A referral out of the organization. A decision to do nothing, documented, so that a pattern is visible if it recurs.
That answer does more work than any other single input, because it determines three separate things at once: what may lawfully be collected, who has to be told, and when the file has to go. An investigation launched without it tends to expand to fill the available records, and an investigation that expands to fill the available records is exactly the one that collects material nobody can later justify collecting.
If the honest answer is "we don't know yet, we just want to see", that is a real answer — but it is a narrower mandate than it feels like, and it should be written down as the narrow thing it is.
Three movements, three sections, one duty each
The Act treats what an employer does with employee personal information as three distinct acts, and gives each its own section.
Collection — s.13. Pulling the logs, the footage, the mailbox, the notes. The Act permits an employer to collect employee personal information without consent where the collection is reasonable for the purpose of establishing, managing or terminating an employment relationship, and it attaches a duty: notify the individual that the information will be collected, and the purposes for it.
Use — s.16. Reading it, analysing it, comparing badge times against a shift roster, building a timeline. Same structure: permitted without consent where reasonable for that employment purpose, with a duty to notify the individual that the information will be used and why.
Disclosure — s.19. Handing it to somebody outside the organization, or to a party the individual would not expect. External counsel. An insurer. An investigator. A parent company. The Act carries the same structure again, and the same duty to notify.
Three things are worth pulling out of that pattern.
The first is that the permission and the duty are a package. The route these sections open is the without consent route, and notification is what the Act asks in return for it. Employers frequently take the permission and skip the price, usually because nobody realised the price was there.
The second is that they are separate acts. An employer who told an employee, once, at hiring, that "systems are monitored" has not thereby notified them about a targeted review of three months of their own movements for the purpose of deciding whether to end their employment. Collection notice is not use notice, and neither is disclosure notice.
The third is a limit on this article rather than on you. Each of these sections sits in a longer part of the Act, and each carries qualifications and exceptions in provisions we are not summarising here. We are not going to imply the duty is absolute and unqualified — it is not a free-floating rule, and how it applies to a specific investigation, particularly one where notifying the individual in advance would defeat the purpose, is a question for your counsel with the facts in front of them. What we will say is that "we assumed we didn't have to tell them" is not a position anyone should reach by accident.
The sequence is the thing
Notification is not a document you produce at the end. Once a decision has been made, a notice sent afterwards reads as tidying up, and it reads that way to the person receiving it, to an adjudicator, and to anyone reviewing the file later.
Timing questions worth resolving before the first record is pulled, not after:
- Who is being investigated, and are they the only one? A camera review aimed at one person routinely captures four others. Those four are also employees, also in the file, and their information also arrived by collection.
- What is being collected, from which systems, over what window? "Everything, to be safe" is not a scope; it is the absence of one. A defined window is defensible and a fishing licence is not.
- When is the individual told, by whom, and in what words? Somebody has to own this. In most organizations it defaults to nobody.
- Who inside the organization needs to see it? Access to an investigation file is not a perk of seniority. It is use of personal information, and every additional viewer is another person who has used it.
- Is anything leaving the organization? If yes, that is disclosure, and the s.19 duty applies to it in its own right.
If your organization uses an external investigator, the same questions apply to their side of the file — and the statutory limits on how any BC investigator may lawfully gather it are set out in what a BC private investigator can and cannot legally do. Two of the evidence sources employers reach for first have their own dedicated treatment: surveillance evidence in BC and, where the file starts before the person was hired, background checks and consent.
Section 34: the file itself is the exposure
Here is the part employers consistently underrate.
An investigation file is, quite often, the most sensitive material an organization will ever hold about a person. It is not the payroll record. It concerns alleged misconduct, it contains the accounts of colleagues who spoke on the understanding that they would not be named in the lunchroom, it may contain health or family circumstances offered by way of explanation, and its subject is somebody who — until a conclusion is reached — has not been found to have done anything at all.
Section 34 requires an organization to protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks.
Now picture where that file actually lives during a typical investigation. A shared network folder inherited from the last reorganisation, with permissions nobody has audited. Three managers' email inboxes, because the draft was circulated for comment. A USB stick with the exported footage on it, in a drawer. A personal phone, because somebody photographed a page to read on the train. The final report attached to a calendar invite.
Reasonable security arrangements for an investigation file means, concretely: a named custodian, a single storage location with an access list you could recite, no circulation by attachment, exported footage treated as a controlled copy rather than a convenience, and a record of who opened it. It is not exotic. It is just rarely anyone's job.
The same principle applies to the systems the evidence came from in the first place — the access control head end that produced the door logs is itself a store of named movement data, which is the subject of your door logs are personal information.
Section 35: retention cuts both ways
Section 35 is the provision that surprises people, because it pushes in two directions at once and most organizations have only ever thought about one of them.
Keep it long enough. Where an organization uses an individual's personal information to make a decision that directly affects them, it must retain that information for at least one year after using it, so the individual has a reasonable opportunity to obtain access to it. An investigation that supported a dismissal is the textbook case. The instinct to close the file and clear the drive the week after the person leaves is the wrong instinct, and it is wrong in a way that is very hard to explain afterwards.
Do not keep it forever. The Act also requires an organization to destroy documents containing personal information, or remove the means by which the information can be associated with particular individuals, as soon as it is reasonable to assume that the purpose it was collected for is no longer served and retention is no longer necessary for legal or business purposes.
Between those two edges sits a decision somebody has to make deliberately. In practice, four things usually need separating: the report and its conclusion, the underlying evidence, the incidental material that swept in other people, and the working copies. They rarely deserve the same retention period, and the working copies almost never deserve to exist a month after the file closes.
If the investigation cleared the person, that is not a reason to keep the file indefinitely "in case". A file kept against a purpose nobody can articulate is the definition of retention past its purpose.
Everyone else in the file
The sections above govern employee personal information. Investigation files are rarely that tidy. A complainant may be a customer. A witness may be a contractor. A named third party may have no relationship with your organization at all. Different provisions of the Act govern their information, and we are deliberately not compressing that into a paragraph here — it deserves proper treatment rather than a summary confident enough to be wrong.
The practical consequence is simply this: when you scope an investigation, count the people in the file, not the person the file is about.
What good looks like
An investigation that will survive being examined tends to share the same handful of features. The decision it was meant to support was written down at the start. The scope was defined and the collection matched it. The individual was notified, and someone owned that. Access to the file was a list, not a culture. Observation is separated from inference in the report. And the retention decision was made on purpose, at the close, with the one-year floor and the destruction obligation both on the table.
None of that makes an investigation harder to run. It makes it survivable, which is a different and more useful property.
If you are at the beginning of one and the first question — what decision is this meant to support — does not yet have an answer, that is the most useful place to stop and think. Guard Nation holds a private investigator licence in British Columbia, and the conversation we would rather have is that one, before the first record is pulled.
Sources
- Personal Information Protection Act, SBC 2003, c. 63, s.13 (collection of employee personal information) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
- Personal Information Protection Act, SBC 2003, c. 63, s.16 (use of employee personal information) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
- Personal Information Protection Act, SBC 2003, c. 63, s.19 (disclosure of employee personal information) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
- Personal Information Protection Act, SBC 2003, c. 63, s.34 (protection of personal information) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
- Personal Information Protection Act, SBC 2003, c. 63, s.35 (retention and destruction) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
