🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CA-AB v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing18 sources retrieved model claude-sonnet-5 · 2026-08-05

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Alberta, Canada

CA-AB schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: AIC

Last updated · 10 categories · 38 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
38Claimsbaseline..claims[]
13Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 21 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Alberta's private-sector privacy statute, PIPA, remains without an amendment bill despite the Standing Committee's 12 recommendations having been published in February 2025, and as of June 2026 no such bill had been introduced into the Alberta Legislature. This standing gap matters more this cycle because of a parallel federal development: Bill C-36, the Protecting Privacy and Consumer Data Act, had its first reading on 15 June 2026 and explicitly preserves Alberta PIPA's substantially-similar provincial exemption from PIPEDA, but the preservation carries a maintenance risk if Alberta does not eventually amend PIPA to match C-36's new federal requirements. Alberta and British Columbia are the only two provinces whose private-sector privacy law has been deemed substantially similar to the federal standard, so any erosion of that status would be a structurally significant event, though nothing in the evidence this cycle indicates the designation is currently under formal review.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A mature, judicially-tested private-sector statute with a dedicated independent regulator and clear substantially-similar status vis-à-vis federal law.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — GreenA mature, judicially-tested private-sector statute with a dedicated independent regulator and clear substantially-similar status vis-à-vis federal law.

Sub-modules (5)

Regulator And AuthorityGreen

OIPC enforces PIPA, HIA and POPA/ATIA and reports directly to the Legislature as an independent Officer.

Claims (1):

  • The Office of the Information and Privacy Commissioner of Alberta (OIPC) enforces PIPA and reports to the Officer of the Legislature.

Act And InstrumentsGreen

PIPA is the core private-sector instrument; HIA governs health custodians; POPA/ATIA govern the public sector post-2024 split.

Claims (2):

  • The Personal Information Protection Act, SA 2003, c P-6.5 (PIPA) is the primary act protecting personal data in Alberta's private sector.
  • Alberta separated its public-sector access/privacy law in 2024, replacing the FOIP Act with the Access to Information Act (ATIA) and the Protection of Privacy Act (POPA), following Bill 33/Bill 34 royal assent on December 5, 2024.

Material ScopeGreen

PIPA governs collection, use and disclosure of personal information by organizations for purposes a reasonable person would consider appropriate; FOIP/POPA-covered information is excluded from PIPA's scope.

Claims (1):

  • PIPA governs the collection, use and disclosure of personal information by organizations in a manner recognizing both individual protection rights and organizations' need to process information for purposes a reasonable person would consider appropriate.

Territorial ScopeAmber

No explicit extraterritorial/establishment test for PIPA was identified in the sources reviewed; PIPA applies to organizations operating in Alberta, with PIPEDA governing inter-provincial/international commercial flows by the same organizations.

Absence provenance: unavailable. Searched: Alberta PIPA extraterritorial application scope, PIPA non-established organization application.

Regulator Registration And FilingAmber

PIPA empowers the OIPC to comment on Privacy Impact Assessments (PIAs) submitted by organizations, notably for biometric identity-verification services, functioning as a de facto filing/consultation channel rather than a general registration regime.

Claims (1):

  • The OIPC's powers include commenting on the implications of Privacy Impact Assessments (PIAs) submitted to it by organizations.
Category narrative98 words

Alberta's private-sector data protection regime is anchored in the Personal Information Protection Act (PIPA), SA 2003, c P-6.5, enforced by the Office of the Information and Privacy Commissioner of Alberta (OIPC). PIPA has been deemed substantially similar to Part 1 of the federal PIPEDA since 2004, which displaces PIPEDA for intra-provincial commercial activity but leaves PIPEDA operative for inter-provincial/international transactions. Alberta's public sector now runs on a separate dual-law model (Protection of Privacy Act/POPA and Access to Information Act/ATIA), both effective following 2024 royal assent, replacing the former FOIP Act, with the OIPC retaining oversight of all regimes.

Sources and claims (5)
  1. ProbableDataGuidance — The Office of the Information and Privacy Commissioner of Alberta (OIPC) enforces PIPA and reports to the Officer of the Legislature.observed
  2. ProbableDataGuidance — The Personal Information Protection Act, SA 2003, c P-6.5 (PIPA) is the primary act protecting personal data in Alberta's private sector.observed
  3. ProbableDataGuidance — Alberta separated its public-sector access/privacy law in 2024, replacing the FOIP Act with the Access to Information Act (ATIA) and the Protection of Privacy Act (POPA), following Bill 33/Bill 34 royal assent on December 5, 2024.observed
  4. ProbableOffice of the Privacy Commissioner of Canada — PIPA governs the collection, use and disclosure of personal information by organizations in a manner recognizing both individual protection rights and organizations' need to process information for purposes a reasonable person would consider appropriate.observed
  5. ProbableDataGuidance — The OIPC's powers include commenting on the implications of Privacy Impact Assessments (PIAs) submitted to it by organizations.observed

#

Core consent/purpose principles are in force, but special-category and anonymisation frameworks remain gaps pending legislative reform.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberCore consent/purpose principles are in force, but special-category and anonymisation frameworks remain gaps pending legislative reform.

Sub-modules (4)

Lawful BasesGreen

PIPA authorizes collection, use and disclosure only for purposes a reasonable person would consider appropriate in the circumstances.

Claims (1):

  • An organization may collect, use or disclose personal information under PIPA only for a purpose that a reasonable person would consider appropriate in the circumstances.

Special CategoriesRed

PIPA has no defined category of 'sensitive personal information'; the OIPC and Alberta's Ministry of Technology and Innovation have proposed adding one covering biometric, children's and intimate information.

Claims (1):

  • PIPA does not currently contain a defined category of sensitive personal information; the OIPC and Alberta's Ministry of Technology and Innovation have recommended creating one covering biometric, children's and intimate information.

Pseudonymisation And AnonymisationRed

PIPA lacks a statutory de-identification/anonymisation framework; the OIPC has recommended one including definitions, standards and re-identification prohibitions.

Claims (1):

  • PIPA lacks a codified framework for de-identified or anonymized information; the OIPC has recommended one including definitions, standards, and prohibitions on re-identification.
Category narrative59 words

PIPA uses a 'reasonable purpose' standard rather than an enumerated lawful-bases list, and its consent regime centres on knowledgeable, reasonably-understandable notice, with a distinct carve-out for 'personal employee information'. PIPA currently has no statutory definition of 'sensitive/special category' information or a codified de-identification/anonymisation framework; both are subjects of active reform recommendations from the OIPC and the federal Privacy Commissioner.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableOffice of the Privacy Commissioner of Canada — An organization may collect, use or disclose personal information under PIPA only for a purpose that a reasonable person would consider appropriate in the circumstances.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — PIPA currently requires organizations to provide notice, in a form the individual can reasonably be considered to understand, of intended collection, use or disclosure purposes.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — PIPA permits organizations to collect 'personal employee information' without consent where reasonable for establishing, managing or terminating an employment or volunteer relationship.observed
  4. ProbableOffice of the Privacy Commissioner of Canada — PIPA does not currently contain a defined category of sensitive personal information; the OIPC and Alberta's Ministry of Technology and Innovation have recommended creating one covering biometric, children's and intimate information.observed
  5. ProbableOffice of the Privacy Commissioner of Canada — PIPA lacks a codified framework for de-identified or anonymized information; the OIPC has recommended one including definitions, standards, and prohibitions on re-identification.observed

#

Access rights are established and in force; portability is aspirational/reform-stage only, and precise deadline figures require primary-source verification.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberAccess rights are established and in force; portability is aspirational/reform-stage only, and precise deadline figures require primary-source verification.

Sub-modules (5)

Access RightGreen

PIPA provides individuals the right to access personal information held by an organization.

Claims (1):

  • PIPA provides individuals the right to access personal data held about them by an organization.

Rectification And ErasureAmber

PIPA imposes correction-related obligations on organizations as part of its access framework; OIPC review materials reference a 'right to erasure' as a reform topic under discussion, implying no fully codified erasure right yet.

Claims (1):

  • A codified 'right to erasure' under PIPA remains a reform-discussion topic rather than a confirmed existing statutory right, per the Alberta Legislative Assembly's PIPA review materials.

Restriction And ObjectionRed

No explicit standalone restriction/objection right distinct from access/correction was confirmed in sources reviewed for PIPA.

Absence provenance: unavailable. Searched: Alberta PIPA right to restrict processing, Alberta PIPA right to object profiling.

Data PortabilityRed

PIPA does not currently include a data portability right; the OIPC has called for amendment to add a 'right to portability and data mobility'.

Claims (1):

  • The Alberta OIPC has called for PIPA to be amended to include a right to portability and data mobility, allowing individuals to obtain or transfer their personal information in a structured, machine-readable format.

Deadlines And Response WindowsAmber

Specific statutory day-count deadlines for PIPA access-request responses were not independently confirmed in the sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA access request response deadline days, PIPA section 28 response time.

Category narrative48 words

PIPA grants individuals a right of access to personal information held by organizations and corresponding correction rights, but currently lacks a codified data-portability right; the OIPC has called for one modeled on the federal CPPA's data-mobility provisions. Specific statutory response-window day-counts were not confirmed in the sources reviewed.

Sources and claims (3)
  1. ProbableDataGuidance — PIPA provides individuals the right to access personal data held about them by an organization.observed
  2. UncertainOffice of the Privacy Commissioner of Canada — A codified 'right to erasure' under PIPA remains a reform-discussion topic rather than a confirmed existing statutory right, per the Alberta Legislative Assembly's PIPA review materials.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — The Alberta OIPC has called for PIPA to be amended to include a right to portability and data mobility, allowing individuals to obtain or transfer their personal information in a structured, machine-readable format.observed

#

Breach notification and accountability-for-transfers are in force and well-precedented, but DPIA/DPO/ROPA/AMPs infrastructure is thin relative to GDPR-style regimes.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberBreach notification and accountability-for-transfers are in force and well-precedented, but DPIA/DPO/ROPA/AMPs infrastructure is thin relative to GDPR-style regimes.

Sub-modules (7)

Accountability And DpiaAmber

OIPC comments on PIAs submitted by organizations; PIPA does not mandate PIAs across the board as a statutory requirement, unlike POPA's public-sector PIA mandate.

Claims (1):

  • The OIPC's powers include commenting on the implications of Privacy Impact Assessments sent to it, though PIPA does not impose a blanket statutory PIA mandate on all organizations.

Dpo RequirementsAmber

No explicit statutory DPO-appointment threshold under PIPA was confirmed; organizations commonly designate an informal 'privacy officer' as a practice matter.

Absence provenance: unavailable. Searched: Alberta PIPA DPO appointment requirement, PIPA privacy officer designation threshold.

Ropa RequirementsRed

No explicit records-of-processing-activities (ROPA) requirement under PIPA was identified in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA records of processing requirement.

Joint Controller ArrangementsGreen

An organization that transfers personal information to a third party for processing remains responsible for that information under PIPA-aligned accountability guidance.

Claims (1):

  • Under joint OPC/Alberta/BC accountability guidance, the law stipulates that an organization transferring personal information to a third party for processing remains responsible for that information.

Security MeasuresAmber

General security-of-processing obligations exist under PIPA's accountability principle; specific technical/organisational measure requirements were not independently itemized in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA security safeguard requirements detail.

Breach NotificationGreen

PIPA requires organizations to notify the OIPC without unreasonable delay of breaches posing a real risk of significant harm (RROSH); Alberta was the first Canadian jurisdiction (2010) to mandate private-sector breach notification. The Health Information Act imposes a parallel harm-based breach-notification regime for custodians.

Claims (3):

  • PIPA requires organizations that suffer a privacy breach to notify the OIPC without unreasonable delay where the breach poses a real risk of significant harm to affected individuals, and the Commissioner may then require notification of affected individuals.
  • Alberta became the first Canadian jurisdiction to implement mandatory breach notification in private-sector privacy legislation, in 2010.
  • The Health Information Act requires custodians to notify affected individuals, the Minister of Health, and the OIPC of privacy breaches meeting a harm-based risk threshold, following a structured risk-of-harm analysis.

Retention And DisposalAmber

No specific statutory retention-period figures under PIPA were confirmed in sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA retention period requirement, PIPA disposal of personal information duty.

Category narrative72 words

PIPA imposes accountability for personal information transferred to third parties for processing, and a mandatory breach-notification duty to the OIPC where a real risk of significant harm (RROSH) exists — Alberta was the first Canadian jurisdiction to adopt breach notification (2010). PIPA currently lacks an administrative monetary penalties (AMPs) regime, a codified ROPA requirement, or an explicit DPO-designation threshold; these remain gap areas versus the federal CPPA proposal and Quebec's Law 25.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Office of the Information and Privacy Commissioner of Alberta mandated a new Privacy Impact Assessment template for public bodies under the Protection of Privacy Act (POPA), effective 1 May 2026. This new template applies specifically to public-body controllers and does not extend to PIPA-governed private-sector organisations, meaning Alberta's private sector continues to operate under whatever PIA practices individual organisations have adopted voluntarily, without a mandated template equivalent to the public-sector one.

This development is understood to be probable rather than confirmed, drawn from a secondary reporting source rather than a directly retrieved primary OIPC or government publication stating the template's mandate in full. It nonetheless represents a tightening of documented accountability expectations for one half of Alberta's dual public/private privacy framework, creating a visible asymmetry between the two sectors' controller/processor duties at a moment when the private-sector PIPA statute itself remains unamended despite years of pending reform recommendations.

The practical effect for organisations operating across both public and private capacities, or contracting with public bodies as processors, is that the new PIA template may create downstream documentation expectations even for private-sector processors supporting public-body controllers, though no evidence this cycle addresses that specific processor-facing question directly.

Outlook

Whether Alberta eventually extends an equivalent PIA template requirement to PIPA-governed private-sector controllers is the key structural question raised by this cycle's public-sector-only measure. Confirming the POPA PIA template's full requirements from a primary OIPC or government source, rather than the secondary reporting currently supporting this finding, would also usefully firm up the current probable-confidence assessment.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableDataGuidance — The OIPC's powers include commenting on the implications of Privacy Impact Assessments sent to it, though PIPA does not impose a blanket statutory PIA mandate on all organizations.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — Under joint OPC/Alberta/BC accountability guidance, the law stipulates that an organization transferring personal information to a third party for processing remains responsible for that information.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — PIPA requires organizations that suffer a privacy breach to notify the OIPC without unreasonable delay where the breach poses a real risk of significant harm to affected individuals, and the Commissioner may then require notification of affected individuals.observed
  4. ProbableIAPP — Alberta became the first Canadian jurisdiction to implement mandatory breach notification in private-sector privacy legislation, in 2010.observed
  5. ProbableIAPP — The Health Information Act requires custodians to notify affected individuals, the Minister of Health, and the OIPC of privacy breaches meeting a harm-based risk threshold, following a structured risk-of-harm analysis.observed

#

Adequacy inheritance via PIPEDA is confirmed and strong, but Alberta-specific transfer mechanisms (SCCs, TIAs, localisation) are not independently codified.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA); Personal Information Protection and Electronic Documents Act (PIPEDA) for trans-border flows
Traffic-light rationale — AmberAdequacy inheritance via PIPEDA is confirmed and strong, but Alberta-specific transfer mechanisms (SCCs, TIAs, localisation) are not independently codified.

Sub-modules (6)

Transfer MechanismsGreen

When Alberta organizations subject to PIPA engage in trans-border personal information flows for commercial reasons, they must follow PIPEDA for those specific transactions.

Claims (1):

  • When Alberta organizations subject to PIPA engage in trans-border personal information flows for commercial reasons, they must follow PIPEDA for those specific transactions.

Adequacy ReceivedGreen

Canada's PIPEDA-based regime (which governs Alberta organizations' international transfers) continues to be found adequate by the European Commission.

Claims (1):

  • Canada's adequacy status under the EU GDPR was reviewed, with the European Commission finding that Canada continues to provide an adequate level of protection for personal information transferred from the EU to recipients subject to PIPEDA.

Adequacy GrantedAmber

No evidence was found of Alberta or Canada granting outbound adequacy-style determinations to other regimes; Canada's model is organization-accountability based rather than state-to-state adequacy granting.

Claims (1):

  • PIPEDA does not prohibit transferring personal information to another jurisdiction for processing but instead governs such transfers through an organization-accountability model rather than adequacy or standard-contractual-clause designations.

Sccs And BcrsAmber

No Alberta-specific SCC or BCR mechanism was identified; PIPEDA's accountability principle (Schedule 1, Principle 1) governs outsourcing/transfer arrangements instead of a formal contractual-clause regime.

Claims (1):

  • PIPEDA does not prohibit transferring personal information to another jurisdiction for processing but instead governs such transfers through an organization-accountability model rather than adequacy or standard-contractual-clause designations.

Transfer Impact AssessmentRed

No standalone Transfer Impact Assessment requirement analogous to GDPR Schrems II practice was identified for PIPA-covered organizations.

Absence provenance: unavailable. Searched: Alberta PIPA transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate for Alberta's private sector was identified in sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA data residency requirement, Alberta private sector data localisation mandate.

Category narrative69 words

PIPA-covered organizations must additionally comply with PIPEDA for trans-border commercial data flows, since Alberta's substantially-similar status only displaces PIPEDA for intra-provincial activity. Canada (and therefore the PIPEDA layer applicable to Alberta organizations' international transfers) retains its EU adequacy status as reaffirmed in the European Commission's most recent review. No SCC/BCR-style formal transfer-mechanism regime or data-localisation mandate specific to Alberta's private sector was identified; the accountability-based (organization-to-organization) model applies instead.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Federal Bill C-36, the Protecting Privacy and Consumer Data Act, had its first reading on 15 June 2026 and explicitly preserves Alberta PIPA's substantially-similar provincial exemption from the federal PIPEDA standard. Alberta and British Columbia are the only two provinces whose private-sector privacy statutes have been deemed substantially similar to PIPEDA, a designation that allows Alberta organisations to be governed by PIPA rather than the federal statute for most private-sector purposes.

However, the preservation clause in C-36 is understood to carry a maintenance risk: if Alberta does not amend PIPA to keep pace with the new requirements C-36 would introduce federally, the substantially-similar designation could, over time, come under pressure, since the designation depends on Alberta's statute remaining broadly equivalent to the federal standard as that standard evolves. This risk sits alongside the separate, longer-running fact that no PIPA amendment bill has been introduced in Alberta despite the Standing Committee's 12 recommendations having been published in February 2025, meaning Alberta's statute has not moved in step with reform pressure even before C-36's first reading raised this new federal-alignment consideration.

This finding is probable rather than confirmed, since it rests on a secondary legal-commentary source's reading of C-36's preservation clause rather than a directly retrieved primary text of the bill itself; the practical mechanics of how and when the substantially-similar designation might be reassessed have not been established in the evidence available this cycle.

Outlook

Whether Alberta responds to C-36's first reading by initiating its own PIPA amendment process, potentially folding in the Standing Committee's 12 recommendations alongside any changes needed to keep pace with the new federal standard, is the central cross-border question to watch. Confirming the exact preservation and reassessment mechanics of C-36's provincial-exemption clause from the bill's primary text, rather than secondary commentary, would also usefully firm up this cycle's probable-confidence assessment.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ProbableOffice of the Privacy Commissioner of Canada — When Alberta organizations subject to PIPA engage in trans-border personal information flows for commercial reasons, they must follow PIPEDA for those specific transactions.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — Canada's adequacy status under the EU GDPR was reviewed, with the European Commission finding that Canada continues to provide an adequate level of protection for personal information transferred from the EU to recipients subject to PIPEDA.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — PIPEDA does not prohibit transferring personal information to another jurisdiction for processing but instead governs such transfers through an organization-accountability model rather than adequacy or standard-contractual-clause designations.observed

#

Health-sector overlay is robust and well-evidenced; employment carve-out is confirmed; financial/credit/insurance/telecoms overlays are evidentiary gaps.

Primary frameworkHealth Information Act, RSA 2000, c H-5 (health sector); PIPA (employment carve-out)
Traffic-light rationale — AmberHealth-sector overlay is robust and well-evidenced; employment carve-out is confirmed; financial/credit/insurance/telecoms overlays are evidentiary gaps.

Sub-modules (7)

Financial Sector OverlayRed

No Alberta-specific financial-sector DP overlay was confirmed in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA financial sector overlay, Alberta banking privacy overlay.

Health Sector OverlayGreen

The Health Information Act imposes mandatory, harm-triggered breach notification on custodians, with tiered offence fines for custodians and affiliates who fail to report.

Claims (2):

  • The Health Information Act requires custodians to notify affected individuals, the Minister of Health and the OIPC of certain privacy breaches that could create a risk of harm, subject to a harm-based trigger and prescribed safe harbours.
  • Under HIA regulations, individual custodians who fail to comply with breach obligations face fines between $2,000 and $10,000, while organizational custodians face fines between $200,000 and $500,000.

Telecoms And EprivacyRed

No Alberta-specific telecoms/ePrivacy overlay distinct from general PIPA/PIPEDA consent principles was confirmed in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA telecoms overlay, Canada ePrivacy cookie law Alberta.

Employment DataGreen

PIPA carves out 'personal employee information' from standard consent requirements where collection is reasonable for managing the employment relationship.

Claims (1):

  • PIPA allows organizations to collect 'personal employee information' without consent where reasonable for establishing, managing, or terminating an employment or volunteer relationship.

Credit And ScoringAmber

No Alberta-specific credit-scoring overlay was confirmed; general PIPEDA/PIPA principles apply to inter-provincial credit-bureau data flows as a trans-border-flow example.

Absence provenance: unavailable. Searched: Alberta PIPA credit scoring regulation, Alberta credit reporting privacy overlay.

EducationAmber

Alberta schools using the PowerSchool Student Information System generated 31 breach notices to the OIPC following a cyberattack affecting 5.2 million Canadians.

Claims (1):

  • A cyberattack on PowerSchool's Student Information System affected 5.2 million Canadians and generated 31 breach notices from Alberta schools reported to the OIPC.

InsuranceRed

No Alberta-specific insurance-sector DP overlay was confirmed in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA insurance sector overlay.

Category narrative66 words

Alberta's health sector is governed by a distinct Health Information Act (HIA) regime with harm-based breach notification and tiered offence penalties, layered atop PIPA/PIPEDA. PIPA itself carves out 'personal employee information' from ordinary consent rules. Education-sector incidents (e.g., the PowerSchool breach affecting Alberta schools) have driven OIPC breach-notice activity. No material Alberta-specific overlays for financial services, credit-scoring, or insurance were confirmed in sources reviewed this run.

Periodic update · new data 2026-09-28

Sectoral Watch

Two sectoral developments are active in Alberta this cycle. In the health sector, Bill 11 introduces significant amendments to the Health Information Act that raise privacy, accountability and AI-in-healthcare concerns, and the OIPC has issued Privacy Impact Assessment guidance specifically addressing AI scribe tools used in clinical settings. This pairing of a legislative amendment with targeted regulator guidance on a specific AI application indicates the health sector overlay is actively moving, with the OIPC positioning itself to address AI-driven clinical documentation tools as they are adopted by Alberta health providers.

In the education sector, the OIPC reported 31 breach notices from Alberta schools using the PowerSchool platform, forming part of a cyberattack reported to have affected 5.2 million Canadians nationally. The scale of the national impact suggests this is not an Alberta-specific vulnerability but rather Alberta's share of a broader Canadian education-sector incident; the 31 notices from Alberta schools represent the locally reportable portion of a much larger cross-jurisdictional breach event.

Both developments are assessed at probable confidence, drawn from secondary reporting rather than directly retrieved primary OIPC breach-notification or health-ministry sources; the exact number of Alberta individuals affected by the PowerSchool breach, as distinct from the national figure, has not been separately confirmed in the evidence available this cycle.

Outlook

Confirming the Alberta-specific individual-count impact of the PowerSchool breach, as distinct from the 5.2 million national figure, from a primary OIPC source would clarify the scale of this cycle's most significant sectoral data event. On the health-sector track, watching how Bill 11 progresses through the Legislature and whether the OIPC's AI scribe guidance evolves into a more formal instrument would clarify whether the health-sector overlay is moving toward a durable new compliance requirement or remains guidance-level for now.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ProbableIAPP — The Health Information Act requires custodians to notify affected individuals, the Minister of Health and the OIPC of certain privacy breaches that could create a risk of harm, subject to a harm-based trigger and prescribed safe harbours.observed
  2. ProbableIAPP — Under HIA regulations, individual custodians who fail to comply with breach obligations face fines between $2,000 and $10,000, while organizational custodians face fines between $200,000 and $500,000.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — PIPA allows organizations to collect 'personal employee information' without consent where reasonable for establishing, managing, or terminating an employment or volunteer relationship.observed
  4. ProbableDataGuidance — A cyberattack on PowerSchool's Student Information System affected 5.2 million Canadians and generated 31 breach notices from Alberta schools reported to the OIPC.observed

#

This module carries an explicit evidentiary gap; Alberta has no adtech-specific statute distinct from PIPA's general consent regime.

Traffic-light rationale — Not assessedThis module carries an explicit evidentiary gap; Alberta has no adtech-specific statute distinct from PIPA's general consent regime.

Sub-modules (6)

Cookies And TrackersRed

No Alberta-specific cookie/tracker consent statute was identified.

Absence provenance: unavailable. Searched: Alberta PIPA cookies tracker consent regulation.

Dark PatternsRed

No Alberta-specific dark-pattern prohibition was identified.

Absence provenance: unavailable. Searched: Alberta PIPA dark patterns prohibition.

Opt Out SignalsRed

No Alberta-specific recognition of Global Privacy Control or similar opt-out signals was identified.

Absence provenance: unavailable. Searched: Alberta PIPA Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Alberta-specific clean-room/data-collaboration-room rules were identified.

Absence provenance: unavailable. Searched: Alberta PIPA clean room data collaboration rules.

Cross Context AdvertisingRed

No Alberta-specific 'sale'/'share' cross-context advertising framework analogous to US state law was identified.

Absence provenance: unavailable. Searched: Alberta PIPA cross-context advertising sale share.

Direct MarketingAmber

No Alberta PIPA-specific direct-marketing consent/suppression regime distinct from general consent principles was identified; Canada's federal anti-spam law (CASL) may apply but was outside the scope confirmed this run.

Absence provenance: unavailable. Searched: Alberta PIPA direct marketing consent rules.

Category narrative50 words

No Alberta-specific statutory regime for cookies/trackers, dark patterns, opt-out signals, clean rooms, cross-context advertising, or direct marketing was identified in the sources reviewed this run; general PIPA consent/purpose principles would apply by extension, but no dedicated adtech rules, GPC-equivalent recognition, or 'sale'/'share' framework analogous to US state laws were found.

#

Strong enforcement precedent on biometrics exists, but no codified statutory ADM-transparency or profiling-restriction provision was confirmed; AI-specific rules are emergent/sector-limited (health).

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA); Health Information Act (AI-in-healthcare overlay)
Traffic-light rationale — AmberStrong enforcement precedent on biometrics exists, but no codified statutory ADM-transparency or profiling-restriction provision was confirmed; AI-specific rules are emergent/sector-limited (health).

Sub-modules (6)

Profiling RestrictionsRed

No standalone statutory profiling-restriction provision under PIPA was confirmed.

Absence provenance: unavailable. Searched: Alberta PIPA profiling restriction provision.

Automated Decision Making TransparencyRed

No standalone ADM-transparency/explanation right under PIPA was confirmed in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA automated decision-making transparency right.

Ai Risk AssessmentsAmber

OIPC has issued guidance for custodians completing PIAs for AI scribe tools under the HIA, and for small custodians on AI use generally; Bill 11 introduces HIA amendments addressing AI in healthcare.

Claims (2):

  • The OIPC of Alberta issued guidance for custodians on completing Privacy Impact Assessments for AI scribe tools under the Health Information Act.
  • Bill 11 introduces amendments to Alberta's Health Information Act addressing privacy, accountability, and AI use in healthcare amid restructuring.

Biometric RegimeAmber

Joint OIPC-Alberta/BC/federal/Quebec investigations found Clearview AI's image scraping constituted inappropriate mass biometric surveillance, and found that Cadillac Fairview's mall-kiosk facial-data collection required express consent that was not obtained.

Claims (2):

  • A joint investigation by the federal, Alberta, British Columbia and Quebec privacy authorities found Clearview AI's scraping of images and creation of biometric facial-recognition arrays constituted inappropriate mass identification and surveillance of individuals.
  • A joint investigation with the Alberta and BC privacy commissioners found that Cadillac Fairview's collection of facial images and biometric data via mall directory kiosks required express consent that had not been validly obtained.

Genetic DataAmber

The OIPC issued a public alert on privacy risks to Albertans' genetic data following 23andMe's asset sale to TTAM, emphasizing PIPA-based data protection obligations, though this is guidance rather than a distinct statutory genetic-data regime.

Claims (1):

  • Alberta's OIPC alerted citizens to privacy risks following 23andMe's asset sale to TTAM, emphasizing data protection obligations under PIPA for genetic information.

State Surveillance CarveoutsRed

No specific Alberta PIPA state-surveillance/national-security carveout provision was confirmed in sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA national security exemption, PIPA state surveillance carveout.

Category narrative81 words

While PIPA has no dedicated statutory ADM-transparency or profiling-restriction provisions, the Alberta OIPC has been an active co-investigator in major biometric-privacy enforcement matters (Clearview AI, Cadillac Fairview facial-recognition kiosks), establishing strong precedent that express consent is required for biometric collection and that mass biometric scraping is an inappropriate purpose. Alberta is also actively regulating AI use in the health sector via HIA amendments (Bill 11) and OIPC PIA guidance for AI scribe tools, though this remains partly in a reform/rollout stage.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

The OIPC alerted Alberta citizens to privacy risks arising from 23andMe's asset sale to TTAM, a matter that falls under PIPA given the genetic data involved in the transaction. Genetic data of this kind sits among the most sensitive categories of personal information Alberta's private-sector statute addresses, and an asset sale involving a genetic-testing company's data holdings raises the kind of downstream-use and consent questions that biometric and algorithmic governance frameworks are generally designed to anticipate.

This alert is assessed at probable confidence, drawn from secondary reporting rather than a directly retrieved primary OIPC alert page, and the specific scope of the OIPC's warning, including whether it addresses consent-transfer mechanics, data-retention obligations on the acquiring entity, or simply flags the transaction for public awareness, has not been established in the evidence available this cycle.

This development sits alongside, but is evidentially distinct from, the health-sector AI scribe guidance the OIPC has issued this cycle; both reflect an active OIPC posture toward emerging categories of sensitive-data risk, genetic data on one hand and AI-processed clinical data on the other, without yet amounting to a new statutory instrument specific to either category.

Outlook

Confirming the specific content and legal basis of the OIPC's 23andMe/TTAM alert from a primary OIPC source would clarify what, if any, concrete guidance Alberta residents or affected organisations should draw from it. More broadly, whether the OIPC's active posture toward genetic and AI-processed data this cycle develops into a more formal algorithmic or biometric governance instrument, rather than case-by-case alerts and guidance, is the structural question to watch.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableDataGuidance — The OIPC of Alberta issued guidance for custodians on completing Privacy Impact Assessments for AI scribe tools under the Health Information Act.observed
  2. ProbableDataGuidance — Bill 11 introduces amendments to Alberta's Health Information Act addressing privacy, accountability, and AI use in healthcare amid restructuring.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — A joint investigation by the federal, Alberta, British Columbia and Quebec privacy authorities found Clearview AI's scraping of images and creation of biometric facial-recognition arrays constituted inappropriate mass identification and surveillance of individuals.observed
  4. ProbableOffice of the Privacy Commissioner of Canada — A joint investigation with the Alberta and BC privacy commissioners found that Cadillac Fairview's collection of facial images and biometric data via mall directory kiosks required express consent that had not been validly obtained.observed
  5. ProbableDataGuidance — Alberta's OIPC alerted citizens to privacy risks following 23andMe's asset sale to TTAM, emphasizing data protection obligations under PIPA for genetic information.observed

#

Age-of-majority baseline is confirmed, but dedicated minor-specific consent/profiling provisions in PIPA are absent or reform-stage only.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberAge-of-majority baseline is confirmed, but dedicated minor-specific consent/profiling provisions in PIPA are absent or reform-stage only.

Sub-modules (5)

Age VerificationAmber

Alberta's age of majority is 18; no PIPA-specific age-verification mandate for data processing was identified.

Claims (1):

  • The age of majority in Alberta is 18, as referenced in federal breach-reporting guidance distinguishing provincial age-of-majority thresholds.

Minor Profiling BansRed

No PIPA-specific minor-profiling ban was identified; children's information has only been proposed as a sensitive-category addition.

Claims (1):

  • Alberta's Ministry of Technology and Innovation proposed that PIPA create a specific category of sensitive personal information including children's information, though this has not been enacted.

Education SettingsAmber

Alberta schools using the PowerSchool Student Information System generated 31 breach notices to the OIPC involving unauthorized access to students' personal information.

Claims (1):

  • The OIPC reported 31 breach notices from Alberta schools using the PowerSchool Student Information System, involving unauthorized access to students' personal information.

Dependent AdultsRed

No Alberta PIPA-specific dependent-adult/vulnerable-adult data protection provision was identified in sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA dependent adult data protection provision.

Category narrative56 words

Alberta's age of majority is 18, but PIPA does not have a distinct statutory consent-age threshold or parental-consent mechanism separate from its general reasonable-person standard; children's information has been proposed (not yet enacted) as a category of sensitive information. Education-sector incidents (PowerSchool breach) have directly implicated minors' data. No dependent-adults-specific provisions were confirmed in sources reviewed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableOffice of the Privacy Commissioner of Canada — The age of majority in Alberta is 18, as referenced in federal breach-reporting guidance distinguishing provincial age-of-majority thresholds.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — Alberta's Ministry of Technology and Innovation proposed that PIPA create a specific category of sensitive personal information including children's information, though this has not been enacted.observed
  3. ProbableDataGuidance — The OIPC reported 31 breach notices from Alberta schools using the PowerSchool Student Information System, involving unauthorized access to students' personal information.observed

#

Strong order-making and offence provisions are in force with active joint enforcement, but the absence of an AMPs regime is a material capability gap relative to peer regimes (Quebec, EU, UK).

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberStrong order-making and offence provisions are in force with active joint enforcement, but the absence of an AMPs regime is a material capability gap relative to peer regimes (Quebec, EU, UK).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

OIPC has binding order-making powers under PIPA not subject to appeal to an external tribunal, and PIPA creates an offence for wilfully attempting to gain unauthorized access to personal information.

Claims (2):

  • Unlike the federal OPC's orders under the proposed CPPA, the Alberta OIPC's orders are not subject to appeal by an external tribunal, only to judicial review by a court.
  • Section 59(1) of Alberta's PIPA makes it an offence to wilfully attempt to gain or gain access to personal information in contravention of the Act.

Enforcement Activity IndexGreen

The OIPC has been active in joint investigations (Clearview AI, Cambridge Analytica/Facebook, Tim Hortons, TikTok, OpenAI, tenant-screening/background-check services) alongside the federal OPC, BC and Quebec regulators.

Claims (1):

  • The federal Privacy Commissioner conducts joint investigations with the Alberta OIPC and other provincial counterparts, including cases such as Clearview AI, Facebook/Cambridge Analytica, Tim Hortons, OpenAI, TikTok, and an ongoing tenant-screening/background-check services investigation.

Regulator Funding And CapacityAmber

No specific OIPC Alberta headcount or budget figures were confirmed in sources reviewed this run.

Absence provenance: unavailable. Searched: OIPC Alberta budget headcount capacity 2026.

Collective Redress And Class ActionsAmber

No PIPA-specific collective-redress or class-action mechanism was confirmed distinct from general Alberta civil procedure in sources reviewed.

Absence provenance: unavailable. Searched: Alberta PIPA class action privacy breach.

Private Right Of ActionAmber

No explicit PIPA private-right-of-action provision distinct from OIPC complaint/order processes was confirmed in sources reviewed this run.

Absence provenance: unavailable. Searched: Alberta PIPA private right of action court damages.

Recent Developments 180DGreen

Public-body privacy-management-program obligations under POPA took full effect June 11, 2026 (end of a one-year grace period), and a new mandatory PIA template for public bodies under POPA started May 1, 2026.

Claims (2):

  • Public bodies in Alberta are required to implement a privacy management program by June 11, 2026, when the one-year grace period under the Protection of Privacy Act expires.
  • Alberta's OIPC mandated a new Privacy Impact Assessment template for public bodies to standardize compliance with POPA starting May 1, 2026.
Category narrative106 words

The OIPC holds binding order-making powers under PIPA (s.52-equivalent authority), not subject to appeal to an external tribunal (only judicial review), and PIPA creates offences including wilfully attempting to gain unauthorized access to personal information (s.59(1)). Alberta's PIPA, like PIPEDA, currently lacks an administrative monetary penalties (AMPs) regime — Quebec's CAI remains the only Canadian privacy regulator with AMP powers. The OIPC is an active participant in joint multi-jurisdictional investigations (Clearview AI, Cambridge Analytica/Facebook, Tim Hortons, TikTok, OpenAI, tenant-screening/background-check services). Recent developments include the POPA privacy-management-program mandate taking full effect June 11, 2026, and a new mandatory PIA template for public bodies from May 1, 2026.

Periodic update · new data 2026-09-28

Enforcement & Redress

Alberta's enforcement-and-redress landscape continues to be shaped by a standing structural constraint: the OIPC lacks direct fining power under PIPA, with its authority limited to investigating complaints, issuing findings, and ordering compliance. The Standing Committee has recommended new sanctioning powers as part of its broader PIPA reform package, but these have not been enacted, meaning the OIPC's enforcement toolkit remains investigatory and declaratory rather than punitive for private-sector matters.

Against that standing backdrop, the OIPC is this cycle actively handling an incident involving the List of Electors that was made public on 30 April 2026. This is a live matter under active OIPC handling, sourced directly from a primary OIPC resource page, though the incident's ultimate disposition, including any findings or recommendations the OIPC may issue, has not yet been reported in the evidence available this cycle. The List of Electors sits within the public-sector, ATIA-adjacent side of Alberta's tri-statute privacy framework rather than the private-sector PIPA track where the OIPC's fining-power limitation applies.

The juxtaposition of a well-documented structural enforcement-power gap on the private-sector side with an active, ongoing public-sector-adjacent incident illustrates the breadth of matters the OIPC handles despite its limited sanctioning authority: it can investigate and report on incidents across all three statutes it supervises, but its power to compel remedy differs materially depending on which statute and which sector is implicated.

Outlook

The disposition of the List of Electors incident is the clearest near-term development to watch, since any findings or recommendations the OIPC issues will clarify how the regulator handles a live incident within its declaratory but non-punitive authority. Separately, whether the Standing Committee's recommended sanctioning powers are ever introduced as part of a future PIPA amendment bill remains the standing structural question for Alberta's enforcement-and-redress framework generally.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableOffice of the Privacy Commissioner of Canada — Unlike the federal OPC's orders under the proposed CPPA, the Alberta OIPC's orders are not subject to appeal by an external tribunal, only to judicial review by a court.observed
  2. ProbableOffice of the Privacy Commissioner of Canada — Section 59(1) of Alberta's PIPA makes it an offence to wilfully attempt to gain or gain access to personal information in contravention of the Act.observed
  3. ProbableOffice of the Privacy Commissioner of Canada — The federal Privacy Commissioner conducts joint investigations with the Alberta OIPC and other provincial counterparts, including cases such as Clearview AI, Facebook/Cambridge Analytica, Tim Hortons, OpenAI, TikTok, and an ongoing tenant-screening/background-check services investigation.observed
  4. ProbableIAPP — Public bodies in Alberta are required to implement a privacy management program by June 11, 2026, when the one-year grace period under the Protection of Privacy Act expires.observed
  5. ProbableDataGuidance — Alberta's OIPC mandated a new Privacy Impact Assessment template for public bodies to standardize compliance with POPA starting May 1, 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct72.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Alberta, Canada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s) (38 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Modules regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, sectoral_watch (health), algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress are well-evidenced with T2 (federal OPC official commentary on Alberta's regime, joint-investigation guidance) and T3 (IAPP, DataGuidance) sources. cross_border_and_adequacy relies primarily on T2 federal OPC materials since Alberta-specific transfer rules are inherited via the PIPEDA layer. data_subject_rights and children_and_vulnerable_groups are partially evidenced (access right confirmed; portability, erasure, and minor-specific provisions are reform-stage or unconfirmed). adtech_and_commercial_privacy and several sub-modules across controller_processor_duties (ROPA, DPO thresholds, retention periods) and sectoral_watch (financial, telecoms, insurance) carry explicit absent_field_provenance gaps — no comprehensive Alberta-specific regime was located for these areas in this run's searches. No T1 primary statute full-text URLs were directly verified this run (PIPA/HIA/POPA citations rest on T2/T3 secondary confirmation of statute names and chapter numbers); this is flagged for primary-source escalation.

Unresolved questions (6):

  • What are PIPA's exact statutory response-window day-counts for access requests (e.g., 45-day analog)?
  • What specific retention-period limits, if any, does PIPA impose on organizations?
  • Has Bill 11 (HIA AI amendments) received royal assent, and what is its current commencement status?
  • Does PIPA contain any explicit ROPA or DPO-designation threshold not captured in secondary sources?
  • Is there a CASL-based direct marketing overlay applicable to Alberta organizations that should be captured under adtech_and_commercial_privacy or sectoral_watch?
  • What is the current, primary-source-verified full legislative citation and URL for the Protection of Privacy Act (POPA) and the Health Information Act (HIA)?

Escalate to primary-source review: yes