Alberta · Personal Information Protection Act

Run Alberta PIPA, including Canada's oldest breach-notification duty

For private-sector organizations, non-profits, and associations operating in Alberta — AccessPoint manages access and correction on the 45-day clock, and the s.34.1 duty to notify the Commissioner of a breach posing a real risk of significant harm.

Alberta — PIPA at a glance

Access deadline
45 days, with an extension in the circumstances PIPA allows
Correction
Correction, or annotation where the organization declines
Breach duty
s.34.1 — notify the Commissioner without unreasonable delay where there is a real risk of significant harm
Who is covered
Private-sector organizations, non-profits, and associations operating in Alberta
Oversight
OIPC of Alberta — order-making
Languages
English, French

Built for Alberta — PIPA

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

The s.34.1 breach duty

Alberta required breach reporting to its Commissioner long before the rest of Canada. Log the incident, assess whether there is a real risk of significant harm, and produce the report with its reasoning intact — including the decisions not to notify.

Access requests on the 45-day clock

Run an individual's access request end to end, covering the information held, how it was used, and to whom it was disclosed, with PIPA's exceptions applied and cited.

Correction and annotation

Manage correction requests, and where the organization declines to correct, record the annotation so the individual's disagreement travels with the record.

Consent, purpose, and disclosure

Record the purpose and authority behind each collection, use, and disclosure, so the basis for holding information can be explained years later.

Built for an order-making regulator

The OIPC of Alberta can order an organization to act. Every request and incident carries a timestamped trail of what was decided, by whom, and on what ground.

In your own tenant

Personal information stays inside your own Microsoft 365 and Azure tenant — no third-party cloud, no vendor access, and no cross-border transfers.

The decision not to notify

s.34.1 turns on a judgment call — and the judgment is what gets reviewed.

Alberta's breach-notification duty is triggered by a standard, not a threshold: an organization must report to the Commissioner where an incident involves a real risk of significant harm to an individual. Most incidents are genuinely below that line, and deciding so is a legitimate outcome. What organizations get wrong is the record. When the OIPC later asks why an incident was not reported, an email thread and a recollection are a weak answer; a dated assessment naming the information involved, the sensitivity, the probability of misuse, and the person who made the call is a strong one. AccessPoint runs every incident through the same assessment whether or not it ends in a report — so the file is equally defensible in both directions.

Assess every incident The same analysis whether or not it reaches the threshold.
Report without delay The Commissioner notification worked as a live checklist.
Defensible either way A dated record behind the decision not to notify.

Configured out of the box

Installing the ca-ab-pipa jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • Alberta PIPA as the legal-authority spine, with access and correction as the workflow
  • The 45-day access clock with PIPA's extension grounds and Alberta's statutory-holiday calendar
  • Access responses covering the information held, its uses, and its disclosures
  • PIPA's exceptions to access, colour-coded for redaction and citable line by line
  • Correction requests and the annotation path where the organization declines
  • The s.34.1 real-risk-of-significant-harm assessment driving Commissioner notification
  • Individual notification workflows where the Commissioner requires them
  • OIPC Alberta complaint and inquiry tracking with grounds and dispositions

Alberta — PIPA Questions

Does PIPA or PIPEDA apply to my organization?

For a private-sector organization's activity within Alberta, PIPA applies — it has been deemed substantially similar to PIPEDA and displaces it intra-provincially. PIPEDA still governs federally regulated works and undertakings and information crossing provincial or national borders in commercial activity. AccessPoint ships both as separate packs.

What triggers the s.34.1 duty to notify the Commissioner?

An incident involving the loss of, or unauthorized access to or disclosure of, personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual. AccessPoint runs that assessment on every incident — the information involved, its sensitivity, the probability of misuse — and records the reasoning whether the outcome is to report or not to report.

How is Alberta's clock different from BC's?

Alberta PIPA runs a 45-day access clock; British Columbia's PIPA runs 30 business days. The two Acts share a name and a purpose but differ in their detail, which is why AccessPoint ships them as separate packs rather than one generic western-Canada configuration.

Where does personal information reside?

Entirely within your own Microsoft 365 and Azure tenant. Requests, incidents, records, and audit history never leave your control — no third-party cloud, no vendor access, and no cross-border data transfers.

Run Alberta PIPA in Your Own Tenant

Try AccessPoint free for 30 days, configured for Alberta's private-sector privacy law. No credit card required.

Start Free Trial