home / frameworks / alberta-pipa

// Canadian privacy and cyber law

Personal Information Protection Act (Alberta)

Alberta's Personal Information Protection Act governs how private-sector organizations in the province handle personal information. Organizations must notify the Information and Privacy Commissioner without unreasonable delay when a breach creates a real risk of significant harm.

Alberta

Overview

The Personal Information Protection Act has applied to Alberta's private sector since 2004. It sets rules for consent, reasonable collection, use, and disclosure, and gives individuals the right to access and correct their information. Employee personal information gets its own rules, so employers can manage the employment relationship without consent in some cases if they give notice. Public bodies follow separate laws. Health custodians fall under the Health Information Act.

Amendments made in 2009 added section 34.1. An organization with personal information under its control must notify the Commissioner without unreasonable delay of any loss of, unauthorized access to, or disclosure of that information where a reasonable person would consider there is a real risk of significant harm to an individual. The Commissioner can then require the organization to notify affected individuals under section 37.1. Failing to notify the Commissioner is an offence. Fines reach $10,000 for an individual and $100,000 for any other person, and the OIPC publishes its breach notification decisions.

Change is under discussion. The Standing Committee on Resource Stewardship reported on its review of the Act in February 2025 and made 12 recommendations, including giving the Commissioner power to impose administrative monetary penalties. The government ran a public engagement on modernizing PIPA in 2026. As of October 11, 2026 no amending bill had been introduced, so the 2003 Act, as amended, remains the law.

Who it applies to in Canada

Provincially regulated private-sector organizations in Alberta, such as corporations, partnerships, unincorporated associations, and trade unions, for both customer and employee personal information. Non-profit organizations are covered only for personal information handled in connection with a commercial activity.

Alberta PIPA is recognized as substantially similar to PIPEDA, so it applies instead of the federal law for most private-sector activity in the province. It has had mandatory breach reporting to the Commissioner since 2010, years before the federal requirement.

Controls at a glance

The Act is organized in parts covering general rules, consent, collection, use and disclosure, access and correction, care of information, and enforcement.

Accountability and policies

  • Designate individuals responsible for compliance
  • Develop and follow reasonable privacy policies and practices
  • Make policy information available on request
  • Disclose use of service providers outside Canada

Consent and purposes

  • Get consent unless an exception applies
  • Give notice of purposes at or before collection
  • Accept deemed or opt-out consent where reasonable
  • Allow withdrawal of consent on reasonable notice

Collection, use, and disclosure

  • Limit to purposes a reasonable person would accept
  • Collect, use, and disclose only what's reasonable
  • Apply listed exceptions for disclosure without consent

Employee personal information

  • Use only for managing the employment relationship
  • Notify employees before collecting without consent
  • Keep collection reasonable for the purpose

Access and correction

  • Respond to access requests within 45 days
  • Correct errors or annotate the record
  • Charge only a reasonable fee for access

Care of personal information

  • Make reasonable security arrangements
  • Keep information accurate and complete
  • Retain only as long as reasonably required

Breach notification

  • Assess real risk of significant harm
  • Notify the Commissioner without unreasonable delay
  • Notify individuals when the Commissioner requires it
  • Answer the Commissioner's follow-up questions

Certification and assessment

There is no certification. The OIPC reviews breach notifications, investigates complaints, and can hold inquiries and issue binding orders. Offences are prosecuted in court, where fines are set.

Dates to know

2004-01-01
Personal Information Protection Act comes into force
2010
Mandatory breach notification to the Commissioner (section 34.1) takes effect
2025-02-28
OIPC responds to the Standing Committee report on its PIPA review
2026-02-02
Government of Alberta opens public engagement on modernizing PIPA

Resources

Official texts and free tools for Alberta PIPA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Personal Information Protection Act (SA 2003, c. P-6.5), Alberta King's Printer
  2. Guidance for Notifying the OIPC about a Privacy Breach Under PIPA, Office of the Information and Privacy Commissioner of Alberta
  3. Information and Privacy Commissioner generally pleased with recent report on Personal Information Protection Act, Office of the Information and Privacy Commissioner of Alberta
  4. Personal Information Protection Act engagement, Government of Alberta
  5. PIPA breach report, Office of the Information and Privacy Commissioner of Alberta