AIBC

Architectural Institute of British Columbia

  • AIBCRegister
  • RegistrantLogin
  • Contact Us
Menu
  • About
    • Organization
    • Regulatory Authority
    • Governance
    • Professional Governance Act Transition
    • Committees & Advisory Groups
    • Annual General Meeting
    • Opportunities
    • Staff
    • Contact Us
    • Close
  • Registration
    • Become an Architect AIBC
    • Architects
    • Intern Architects
    • Architectural Technologists
    • Retired Architects
    • Firm Registrants
    • Temporary Licensee (Architect)
    • Honorary Registrants (Legacy) – Formerly “Honorary Members”
    • Good Standing
    • Professional Mobility
    • Annual Renewal
    • Close
  • Programs & Services
    • Practice Advice
    • RFPs & Competitions
    • Contracts
    • Certified Professional (CP) Program
    • Post-Disaster Building Assessment
    • AIBC Classifieds
    • Municipal Matrix
    • Close
  • Professional Development
    • Continuing Education System (CES)
    • AIBC Courses & Professional Development
    • Recognized Educational Provider Program
    • Close
  • Protecting the Public
    • AIBC’s Regulatory Role
    • Does Your Project Need an Architect?
    • Complaints
    • Professional Conduct
    • Illegal Practice
    • Close
  • News & Events
    • News
    • Calendar
    • Signature Events & Programs
    • Architectural Walking Tours
    • Media
    • AIBC 100
    • Close
  • Resources
    • AIBC Resources
    • Industry Resources
    • Affiliates
    • AIBC Register
    • Close
Home / Privacy Policy

Privacy Policy

The AIBC is designated as a local public body under the Freedom of Information and Protection of Privacy Act, R.S.B.C. 1996, c. 165 (FIPPA). The AIBC’s accountability for the collection, use, disclosure of, and access to, personal information is established under the FIPPA, AIBC Bylaws under the Professional Governance Act, S.B.C. 2018, c. 47 (the “PGA”), and other statutes where applicable.

The Registrar is designated as the head of the AIBC for the purposes of the FIPPA, as per the Bylaws.

Purpose

The AIBC has ethical and legal obligations for the control or custody of personal information about Registrants, contacts including applicants and the public, and employees/contractors. The purpose of this Privacy Policy (“Policy”) is to establish how the AIBC complies with these obligations and demonstrates accountability for managing this information, in a way that respects the privacy of individuals while allowing the AIBC to fulfill its regulatory mandate effectively.

Scope of the Policy

This Policy describes the AIBC’s policies and processes for complying with the FIPPA requirements related to:

  • collection, use, and disclosure of personal information, including notification requirements;
  • accuracy and correction of personal information;
  • protection of personal information; and
  • retention and disposal of personal information.

This Policy also responds to section 36.2 of the FIPPA and related ministerial directions, requiring a privacy management program, which includes the following components, in addition to the items listed below:

  • a process for conducting privacy impact assessments;
  • a publicly-available personal information directory;
  • a process for responding to freedom of information (FOI) requests;
  • a process for responding to privacy breaches; and
  • employee privacy awareness and education.

Read the AIBC’s full Privacy Policy (PDF)

Collection, Use, and Disclosure of Personal Information

Collection of Personal Information

The AIBC collects personal information directly from the subject individual, except in limited circumstances under the FIPPA (section 27) or if collection from another source is authorized by law.

The AIBC collects personal information from Registrants to conduct regulatory functions, including but not limited to:

  • administering regulatory programs and services, including processing applications for registration and reinstatement; investigating complaints; processing continuing education reports, course and examination registrations; and delivering professional development opportunities and practice advice;
  • collecting and processing payments;
  • maintaining a publicly-available register (Registrants and Former Registrants);
  • enabling the Board, Committees, and operational advisory groups to carry out their regulatory functions; and
  • communicating with Registrants regarding regulatory and non-regulatory matters

The AIBC collects the personal information of employees/contractors to manage and compensate them during their engagement and for appropriate record keeping post-employment, and of employment applicants for effective recruitment and selection.

The AIBC may also collect personal information from volunteers, applicants, and members of the public for the purposes of delivering programs and services including, investigating complaints and illegal practice matters, practice advice, processing applications and event registration, and communicating AIBC activities.

Collection Notification

The AIBC provides notification when personal information is collected directly from an individual, which notice includes:

  • the purpose for which the information is being collected;
  • the legal authority under which the information is being collected; and
  • the contact information of a designated officer or AIBC department who can answer questions regarding the collection.

Use and Disclosure of Personal Information

The AIBC controls and monitors access and use of personal information.

The AIBC uses and discloses personal information in its custody or under its control:

  • for the purpose for which the information was obtained or compiled or for a consistent purpose;
  • in the manner to which an individual has consented;
  • as permitted or required by the FIPPA, the PGA, the AIBC Bylaws, or as authorized or required by other law; and
  • to conduct regulatory and administrative functions.

The CEO & Registrar, Deputy CEO, and Deputy Registrars have the authority to request that an employee access and/or disclose the personal information of an Individual Registrant or non-registrant.

Employees are provided access to personal information on a ‘need to know’ basis in order to perform their job functions and responsibilities, and when it is necessary to carry out AIBC operations and activities.

Requests from third parties for disclosure of personal information under section 5 of the FIPPA will be processed as indicated under the Freedom of Information Requests heading of this Policy.

Disclosure of Registrant, non-registrant, or employee personal information by the AIBC in emergency or compelling circumstances will be made in accordance with provisions of the FIPPA.

Accuracy and Correction of Personal Information

The AIBC takes all reasonable steps to ensure the accuracy and completeness of any personal information collected or recorded and is diligent in avoiding errors due to carelessness or other oversights. Employees verify the accuracy of personal information against reliable sources when necessary. During collection, individuals are asked to confirm the accuracy of their information.

Individuals are provided with opportunities to update their personal information at regular intervals where appropriate, such as information about Registrants and employees. If an individual identifies that their personal information is inaccurate or incomplete, they may request correction, as per section 29 of the FIPPA. Employees will promptly correct or update the information as soon as they are discovered or reported and inform any parties to whom the inaccurate or incomplete information has been disclosed. If the correction cannot be made, a note of the requested correction must be added to the file.

Protection of Personal Information

The AIBC is committed to maintaining the security of personal information and other sensitive information, including implementing appropriate security safeguards for its computer and network systems.

The AIBC undertakes regular reviews to update security policies and controls as technology changes to ensure ongoing personal information security.

The AIBC completes privacy impact assessments (PIA) for any proposed or significantly revised system, project, program or activity prior to implementation, in accordance with the FIPPA, and this Policy.

When the AIBC retains an external organization to undertake work on its behalf that involves the collection, use, disclosure, or disposal of personal information, the AIBC enters into an agreement that requires the organization to protect personal information in accordance with the FIPPA and AIBC expectations appropriate to the nature of the services.

AIBC volunteers are required to adhere to a confidentiality and protection of privacy policy to help ensure that AIBC information they may have access to in the course of their volunteer duties is managed in a way that respects privacy.

The AIBC has a responsibility to protect against unauthorized access and disclosure of personal information, including ensuring that access or disclosure is only made to or by authorized individuals, and that reasonable measures are taken to prevent any unauthorized access, disclosure, loss, or theft of information. Proper handling of personal information therefore includes the following practices:

  • hard copies of files and records containing personal information are kept in a secure location, preferably where locked and secured against theft or unauthorized access;
  • available security systems (e.g., locking offices when not in use, activating alarm systems and posting security) are utilized;
  • discussing personal information in public areas where third parties may overhear or view records containing personal information is avoided;
  • removal of records containing personal information from AIBC premises is prohibited except as necessary, and, in such cases the records are kept in a secure location and not exposed to risk of loss, theft or unauthorized access;
  • measures to protect against loss or theft of personal information are in place, including enhanced security of electronic or hard copies of personal information that may be vulnerable to theft or loss; and
  • any potential or actual privacy breach is reported immediately, and according to the Privacy Breach Reporting Policy.

Retention and Disposal of Personal Information

(Note: Detailed retention and disposal schedules are under development.)

Retention of Personal Information

Personal information is retained for as long as required by law, and for a minimum of one year after it has been used to make a decision that directly affects the individual to whom the information pertains, in accordance with the FIPPA.

Personal information is retained beyond the minimum retention period if it is required for operational, legal, or archival purposes.

Retention schedules are clearly documented, and deviations are approved by the appropriate authority.

Disposal of Personal Information

Personal information that is no longer required for operational, legal, or archival reasons is disposed of securely and promptly. The timing and method of disposal is consistent with legal and regulatory requirements.

Records of disposal, including the date and method, are maintained.

Personal information in hardcopy form is shredded or otherwise destroyed in a manner that ensures it cannot be reconstructed or read.

Personal information in electronic form is permanently erased using industry-standard methods to ensure it cannot be recovered. Special procedures are followed to remove data from electronic devices before disposal or redeployment.

Privacy Impact Assessment

A Privacy Impact Assessment (“PIA”) is completed and approved by the privacy officer before implementation or significant change to any program or system that requires the collection, use, or disclosure of personal information.

Personal Information Directory

Section 69(6) of the FIPPA requires the AIBC to make available for public inspection and copying a personal information directory that lists the AIBC’s personal information banks (PIBs). The purpose of making this information available is to help the public know what personal information is in custody of the AIBC.

View the personal information directory (PDF)

The personal information directory describes the types of personal information that the AIBC collects, uses, retains, and discloses, along with the legal authority to do so. The directory includes:

  • the title of each personal information bank;
  • a description of the kind of personal information and the categories of individuals whose personal information is included;
  • the authority for collecting the personal information; and
  • the purposes for which the personal information was collected or compiled and the purposes for which it is used or disclosed, and to whom.

The personal information directory is updated annually according to internal guidelines and is published on the AIBC website.

Freedom of Information (FOI) Requests

Requests for access to records under section 5 of the FIPPA must be made in writing, identifying the information sought, the authority for the request, and the reason for the request.

The AIBC will process access requests in accordance with the FIPPA.

The AIBC reserves the discretion to charge a fee for access request services in accordance with AIBC Bylaw 8.3 and the FIPPA.

Employees may be asked to assist the head of the local public body or privacy officer or others delegated with privacy tasks to assist in processing access requests.

Privacy Breaches

A breach of privacy includes unauthorized access to the AIBC’s physical or electronic records, misdirected communications, including mail, and electronic communications, and the loss or theft of physical records and electronic records stored on portable data storage devices.

The AIBC complies with section 30.5 of the FIPPA, which requires an employee to immediately report an unauthorized disclosure of personal information to the head of the local public body, who is the Registrar in the case of the AIBC.

The AIBC will respond to an internal or external privacy breach according to the Privacy Breach Reporting Policy. The Policy supports the AIBC to effectively:

  • Contain any incidents;
  • Recover as much of the affected information as possible;
  • Assess the harm/impact on affected individuals;
  • Remediate the breach and minimize the harm/impact on affected individuals; and
  • Prevent similar incidents from happening in the future by updating processes, practices, and policies as required, and delivering additional training and awareness.

Employee Privacy Awareness and Education

Employee privacy education activities that support the AIBC’s compliance with the FIPPA is a required component of a privacy management program.  All employees receive training, including but not limited to the following topics:

  • FOIPPA Foundations: Privacy and Access Fundamentals Course
  • FIPPA and employee protection of privacy obligations and responsibilities
  • Personal information banks (PIBs)
  • Handling a potential or actual privacy breach

Role-based training is also provided for activities related to: the Registrant database and acceptable use policies; access to information requests; and the role of the AIBC as a local public body with a public protection mandate, balanced with accountabilities under the FIPPA.



AIBC Contact

Please contact oceo@aibc.ca for more information or questions about the Privacy Policy.

To review the AIBC website privacy policy, please refer to the Website Privacy Policy webpage.

 

Main Pages

  • Home
  • About
  • Registration
  • Programs & Services
  • Professional Development
  • Protecting the Public
  • News & Events
  • Resources

Contact Us

Architectural Institute of B.C.
100 – 440 Cambie Street
Vancouver, British Columbia
Canada V6B 2N5
Tel: 604.683.8588
Email: aibc@aibc.ca

Follow us

Quick Links

  • Sitemap
  • Privacy Policy
  • Website Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2026 AIBC