Alberta's privacy impact assessments under POPA: when section 26 requires one, when it must go to the Commissioner, and what the template expects
The Protection of Privacy Act split Alberta's public-sector privacy law from its access law on June 11, 2025 and made the PIA a statutory duty with a prescribed trigger list. What the Act and the Ministerial Regulation require, the five factors that force submission, the automated-system notice, and where each element lives in AccessPoint — for privacy officers, FOIP coordinators who became POPA coordinators overnight, and the program managers who now need a PIA before launch.
Since June 11, 2025, section 26 of Alberta's Protection of Privacy Act has required every public body to prepare a privacy impact assessment in the circumstances the Ministerial Regulation prescribes, and to submit it to the Information and Privacy Commissioner when any of five factors applies: highly sensitive personal information, a significant share of the population served, data matching, a common or integrated program, or innovative technology. The Commissioner can ask for any other PIA on request, the public body must run a privacy management program with a designated Privacy Officer, and a collection notice must now say whether the information will feed an automated system.
Alberta ran privacy impact assessments for two decades under the old FOIP Act as a matter of practice and Commissioner expectation, and the Health Information Act has required custodians to submit them since its early years. What changed in June 2025 is that the public-sector duty is now in a statute of its own, with the trigger and submission rules written into a regulation, a Commissioner's template public bodies are asked to use, and a head's signature on the submission. If you run access requests, the companion Alberta ATIA guide covers the access half of the split; this guide covers the privacy half that program managers meet first.
What the Act and the regulation require
Section 26 of POPA requires a public body to prepare a PIA in prescribed circumstances and, if the regulations require it, to submit the assessment to the Commissioner in accordance with the regulations. Section 27(1)(j) separately lets the Commissioner request a copy of any public body's PIA as part of monitoring how the Act is administered, so a PIA that was not submitted still has to exist and be producible.
Section 7 of the Protection of Privacy (Ministerial) Regulation sets the trigger. A public body must prepare a PIA for a new, or a substantial change to an existing, administrative practice, program, project or service that involves the collection, use or disclosure of personal information. Where one or more of the following factors applies, the PIA must also be submitted to the Commissioner:
- Highly sensitive personal information. Section 1 of the regulation deems biometric information, financial information, and personal information about a minor, a senior or a vulnerable individual to be of high sensitivity.
- A significant percentage of the population the public body serves.
- Data matching between two or more public bodies, which POPA defines as linking personal information between two or more databases or other electronic sources.
- A common or integrated program or service: one planned, administered, managed, monitored or evaluated collaboratively by public bodies, or by one on behalf of others. The regulation allows two or more public bodies to submit one PIA for such a program.
- Innovative technology.
The OIPC's own guidance draws the line plainly: a public body is required to complete PIAs for qualifying projects whether or not a submission factor applies; it is required to submit them only when one does; and the Commissioner can request copies of the rest. The office publishes a PIA Submission Assessment Tool for the "must we submit" question, updated in May 2026.
The template, the completion guide, and the signature
Public bodies are asked to use the OIPC's POPA PIA Template when submitting, with a companion Completion Guide that explains each section and the evidence the office expects. Two features of the template matter operationally. It asks who the head of the public body is at the time of submission, because the head carries the statutory responsibility and the completion guide states that the head is legally required to sign. And it asks whether the PIA is for a common or integrated program, because section 7(4)(b) of the regulation lets multiple public bodies file one assessment for a shared service.
The template follows the shape every Canadian regulator now expects: the project and its legal authority, the flow of personal information through collection, use, disclosure, retention and destruction, the privacy and security risks, and the controls that mitigate them. Submissions go to the office by email, and the Commissioner reviews and comments rather than approves.
The obligations around the assessment
A privacy management program. The Ministerial Regulation requires each public body to run one, including designating a Privacy Officer responsible for day-to-day operation of the Act and for the public body's compliance. The PIA process is a required component of that program, not a stand-alone form.
Privacy incidents. The regulation also sets requirements for privacy incident reporting, so the PIA's risk section and the incident procedure should describe the same harms in the same words.
Automated systems. POPA's collection notice must state the public body's intention, if any, to input the personal information into an automated system to generate content or make decisions, recommendations or predictions. The government's guide defines an automated system as any system, software or process that uses computation to determine outcomes, make or aid decisions, inform policy implementation, collect data or observations, or otherwise interact with individuals and communities. For any project that meets that definition, the PIA is where the automation is described, and an algorithmic impact assessment is the natural companion.
Data matching, derived data and non-personal data. POPA adds rules on data matching, on creating, retaining, using and disclosing data derived from personal information, and on non-personal data. A modern analytics project will trip at least one of them, and the PIA should say which.
Health custodians. Section 64 of the Health Information Act continues to require custodians to submit PIAs to the Commissioner before implementing administrative practices or information systems, or changes to them, that collect, use or disclose health information. A public body that is also a custodian runs two regimes.
Building the program
- Screen every new or changed initiative against the section 7 trigger and the five submission factors, and record the answer. The Submission Assessment Tool is a good screener; a written one inside your intake is better, because it leaves a record the Commissioner can ask for.
- Use the OIPC template as the questionnaire so a submitted PIA and an internal one look the same, and so nothing has to be re-keyed when a project later crosses a submission factor.
- Send program sections to the program. The flows, the vendors, the retention practice and the real safeguards come from the people running the initiative.
- Register risks and controls. The template's risk and mitigation sections are a risk register; keep them as one with owners and dates, because the substantial-change trigger will bring the same project back.
- Route common or integrated programs deliberately. Decide which public body leads the single PIA the regulation allows, and who signs.
- Keep the head's signature and the submission record together with the approved assessment, so a section 27(1)(j) request can be met in a day.
How AccessPoint runs it
AccessPoint's Alberta jurisdiction pack carries the OIPC's POPA PIA template (the March 2026 edition), versioned and pack-maintained, with POPA attached as the governing legal authority; a separate pack covers the Health Information Act for custodians.
Screener for the trigger and the five factors
A template can carry a preliminary screener whose answers decide whether a full assessment is instantiated or a lightweight compliance record is kept, and whose determination is stored with the assessment.
The OIPC template as a questionnaire
, with typed questions: the personal-information inventory as a table, a flow diagram question where the template has a flow narrative, and answers that bind to the subject's record of processing on approval so the register and the PIA agree.
Section delegation
to the people who run the initiative, with autosave, hours and documents, and coordinator approval.
Risks, controls and commitments
: a likelihood-and-impact register with a harm-to-individuals determination, controls from the controls library with a mandatory, recommended, implemented or not-applicable designation, and undertakings tracked to completion.
Automated-system subjects
A subject typed as an automated decision-making system carries its AI/ADM register: owners, intended purpose, model or service, deployment status, human-involvement level and risk classification, with the universal compliance rules for an assessment before production, an ADM notice and human-involvement documentation.
Review, sign-off, freeze and re-assess
A configurable review carries the head's approval; approved assessments are read-only, and the substantial-change trigger goes forward through Re-assess on the same subject, with the reassessment date pulled forward when a subject's purpose changes.
The submission package
The closure tab generates the regulator summary as a document, and the assessment's documents, approvals and activity trail export together for the Commissioner or for a section 27(1)(j) request.
Incidents on the same platform
, with a risk-of-harm register and a notification checklist computed from the governing legislation, so the PIA's harms and the incident procedure stay aligned.
Everything runs in your own Microsoft 365 and Azure tenant, in Canada, beside the ATIA access requests the same office handles.
A readiness checklist
- Confirm POPA applies and whether the Health Information Act also does.
- Designate the Privacy Officer and document the privacy management program the regulation requires.
- Adopt the OIPC POPA PIA template as your standard questionnaire.
- Put the section 7 trigger and the five submission factors into a written screener at intake.
- Update collection notices to state any automated-system use.
- Inventory data-matching, derived-data and non-personal-data activities; each needs a PIA position.
- Decide lead and signatory for common or integrated programs before the first joint PIA.
- Rehearse a Commissioner request for a PIA you did not submit.
Sources
- POPA PIA Template and PIA Template Completion Guide (POPA) — Office of the Information and Privacy Commissioner of Alberta (template page updated August 26, 2026; accessed September 4, 2026). Both quote section 26 of POPA and section 7 of the Ministerial Regulation, including the five submission factors.
- PIA Submission Assessment Tool (May 5, 2026) and Privacy Impact Assessments — OIPC Alberta (section 64 HIA; sections 7(1) and 7(5) of the Ministerial Regulation).
- ATIA and POPA resources — OIPC Alberta (FOIP repealed and replaced by ATIA and POPA on June 11, 2025).
- Protection of Privacy Act Guide — Government of Alberta (privacy management programs and the Privacy Officer, privacy incidents, the automated-system definition and collection-notice content, data matching, derived and non-personal data).
Related reading on this site: Managing Alberta ATIA, AccessPoint for Alberta public bodies, privacy impact assessment software, the companion guides on British Columbia's section 69 PIAs, Ontario's mandatory PIAs and algorithmic impact assessments, or book a demo.
Alberta PIA Questions
Are privacy impact assessments mandatory for Alberta public bodies?
Yes. Section 26 of the Protection of Privacy Act, in force since June 11, 2025, requires a public body to prepare a privacy impact assessment in the circumstances prescribed by the Protection of Privacy (Ministerial) Regulation and, where the regulation requires it, to submit the assessment to the Information and Privacy Commissioner. The Commissioner may also request a copy of any PIA under section 27(1)(j).
When does an Alberta public body have to submit a PIA to the Commissioner?
Section 7 of the Ministerial Regulation requires a PIA for a new, or substantially changed, administrative practice, program, project or service that involves personal information, and requires submission to the Commissioner when any of five factors applies: personal information deemed highly sensitive (biometric, financial, or about a minor, senior or vulnerable individual); a significant percentage of the population the public body serves; data matching between two or more public bodies; a common or integrated program or service; or innovative technology.
Which template do Alberta public bodies use?
The OIPC's POPA PIA Template, with its Completion Guide. The Commissioner's office asks public bodies to use the template when submitting, offers a PIA Submission Assessment Tool for deciding whether a PIA must be completed and whether it must be submitted, and receives submissions by email. The head of the public body signs the submission.
What does POPA say about AI and automated systems?
A collection notice must state the public body's intention, if any, to input the personal information into an automated system to generate content or make decisions, recommendations or predictions. The Act's guide defines an automated system broadly as any system, software or process that uses computation to determine outcomes, make or aid decisions, inform policy implementation, collect data or otherwise interact with individuals. A PIA for such a system should say how the automation works and who oversees it.
What else does POPA require beyond PIAs?
A privacy management program, including a designated Privacy Officer, under the Ministerial Regulation; privacy incident reporting under the same regulation; rules on data matching, on data derived from personal information, and on non-personal data; and the access side now sits in the separate Access to Information Act. Health custodians remain under the Health Information Act, whose section 64 requires PIAs to be submitted before new practices or systems are implemented.