Overview
The Personal Information Protection Act has applied to Alberta's private sector since 2004. It sets rules for consent, reasonable collection, use, and disclosure, and gives individuals the right to access and correct their information. Employee personal information gets its own rules, so employers can manage the employment relationship without consent in some cases if they give notice. Public bodies follow separate laws. Health custodians fall under the Health Information Act.
Amendments made in 2009 added section 34.1. An organization with personal information under its control must notify the Commissioner without unreasonable delay of any loss of, unauthorized access to, or disclosure of that information where a reasonable person would consider there is a real risk of significant harm to an individual. The Commissioner can then require the organization to notify affected individuals under section 37.1. Failing to notify the Commissioner is an offence. Fines reach $10,000 for an individual and $100,000 for any other person, and the OIPC publishes its breach notification decisions.
Change is under discussion. The Standing Committee on Resource Stewardship reported on its review of the Act in February 2025 and made 12 recommendations, including giving the Commissioner power to impose administrative monetary penalties. The government ran a public engagement on modernizing PIPA in 2026. As of October 11, 2026 no amending bill had been introduced, so the 2003 Act, as amended, remains the law.
Who it applies to in Canada
Provincially regulated private-sector organizations in Alberta, such as corporations, partnerships, unincorporated associations, and trade unions, for both customer and employee personal information. Non-profit organizations are covered only for personal information handled in connection with a commercial activity.
Alberta PIPA is recognized as substantially similar to PIPEDA, so it applies instead of the federal law for most private-sector activity in the province. It has had mandatory breach reporting to the Commissioner since 2010, years before the federal requirement.
Controls at a glance
The Act is organized in parts covering general rules, consent, collection, use and disclosure, access and correction, care of information, and enforcement.
Accountability and policies
- Designate individuals responsible for compliance
- Develop and follow reasonable privacy policies and practices
- Make policy information available on request
- Disclose use of service providers outside Canada
Consent and purposes
- Get consent unless an exception applies
- Give notice of purposes at or before collection
- Accept deemed or opt-out consent where reasonable
- Allow withdrawal of consent on reasonable notice
Collection, use, and disclosure
- Limit to purposes a reasonable person would accept
- Collect, use, and disclose only what's reasonable
- Apply listed exceptions for disclosure without consent
Employee personal information
- Use only for managing the employment relationship
- Notify employees before collecting without consent
- Keep collection reasonable for the purpose
Access and correction
- Respond to access requests within 45 days
- Correct errors or annotate the record
- Charge only a reasonable fee for access
Care of personal information
- Make reasonable security arrangements
- Keep information accurate and complete
- Retain only as long as reasonably required
Breach notification
- Assess real risk of significant harm
- Notify the Commissioner without unreasonable delay
- Notify individuals when the Commissioner requires it
- Answer the Commissioner's follow-up questions
Certification and assessment
There is no certification. The OIPC reviews breach notifications, investigates complaints, and can hold inquiries and issue binding orders. Offences are prosecuted in court, where fines are set.
Dates to know
- 2004-01-01
- Personal Information Protection Act comes into force
- 2010
- Mandatory breach notification to the Commissioner (section 34.1) takes effect
- 2025-02-28
- OIPC responds to the Standing Committee report on its PIPA review
- 2026-02-02
- Government of Alberta opens public engagement on modernizing PIPA
Resources
Official texts and free tools for Alberta PIPA. Links open the publisher’s site.
- Personal Information Protection Act (SA 2003, c. P-6.5), Alberta King's Printer
- Personal Information Protection Act, Government of Alberta
- Personal Information Protection Act engagement, Government of Alberta
- Guidance for Notifying the OIPC about a Privacy Breach Under PIPA, Office of the Information and Privacy Commissioner of Albertaguidance
- PIPA breach report, Office of the Information and Privacy Commissioner of Albertatool
Need help? Browse the directory or read the guides.
References
- Personal Information Protection Act (SA 2003, c. P-6.5), Alberta King's Printer
- Guidance for Notifying the OIPC about a Privacy Breach Under PIPA, Office of the Information and Privacy Commissioner of Alberta
- Information and Privacy Commissioner generally pleased with recent report on Personal Information Protection Act, Office of the Information and Privacy Commissioner of Alberta
- Personal Information Protection Act engagement, Government of Alberta
- PIPA breach report, Office of the Information and Privacy Commissioner of Alberta
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.