🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA-AB · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 18 sources retrieved model claude-sonnet-5 ·

Canada – Alberta

CA-AB schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 38 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
38Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A mature, judicially-tested private-sector statute with a dedicated independent regulator and clear substantially-similar status vis-à-vis federal law.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — GreenA mature, judicially-tested private-sector statute with a dedicated independent regulator and clear substantially-similar status vis-à-vis federal law.

Sub-modules (5)

Regulator And AuthorityGreen

OIPC enforces PIPA, HIA and POPA/ATIA and reports directly to the Legislature as an independent Officer.

Claims: CLM-CA-AB-a1b2c3d4

Act And InstrumentsGreen

PIPA is the core private-sector instrument; HIA governs health custodians; POPA/ATIA govern the public sector post-2024 split.

Claims: CLM-CA-AB-b2c3d4e5, CLM-CA-AB-c3d4e5f6

Material ScopeGreen

PIPA governs collection, use and disclosure of personal information by organizations for purposes a reasonable person would consider appropriate; FOIP/POPA-covered information is excluded from PIPA's scope.

Claims: CLM-CA-AB-d4e5f6a7

Territorial ScopeAmber

No explicit extraterritorial/establishment test for PIPA was identified in the sources reviewed; PIPA applies to organizations operating in Alberta, with PIPEDA governing inter-provincial/international commercial flows by the same organizations.

Absence provenance: not recorded. Searched: Alberta PIPA extraterritorial application scope, PIPA non-established organization application.

Regulator Registration And FilingAmber

PIPA empowers the OIPC to comment on Privacy Impact Assessments (PIAs) submitted by organizations, notably for biometric identity-verification services, functioning as a de facto filing/consultation channel rather than a general registration regime.

Claims: CLM-CA-AB-e5f6a7b8

Category narrative98 words

Alberta's private-sector data protection regime is anchored in the Personal Information Protection Act (PIPA), SA 2003, c P-6.5, enforced by the Office of the Information and Privacy Commissioner of Alberta (OIPC). PIPA has been deemed substantially similar to Part 1 of the federal PIPEDA since 2004, which displaces PIPEDA for intra-provincial commercial activity but leaves PIPEDA operative for inter-provincial/international transactions. Alberta's public sector now runs on a separate dual-law model (Protection of Privacy Act/POPA and Access to Information Act/ATIA), both effective following 2024 royal assent, replacing the former FOIP Act, with the OIPC retaining oversight of all regimes.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Office of the Information and Privacy Commissioner of Alberta (OIPC) enforces PIPA and reports to the Officer of the Legislature.
  2. ConfirmedDataGuidanceThe Personal Information Protection Act, SA 2003, c P-6.5 (PIPA) is the primary act protecting personal data in Alberta's private sector.
  3. ConfirmedDataGuidanceAlberta separated its public-sector access/privacy law in 2024, replacing the FOIP Act with the Access to Information Act (ATIA) and the Protection of Privacy Act (POPA), following Bill 33/Bill 34 royal assent on December 5, 2024.
  4. ConfirmedOffice of the Privacy Commissioner of CanadaPIPA governs the collection, use and disclosure of personal information by organizations in a manner recognizing both individual protection rights and organizations' need to process information for purposes a reasonable person would consider appropriate.
  5. ProbableDataGuidanceThe OIPC's powers include commenting on the implications of Privacy Impact Assessments (PIAs) submitted to it by organizations.

#

Core consent/purpose principles are in force, but special-category and anonymisation frameworks remain gaps pending legislative reform.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberCore consent/purpose principles are in force, but special-category and anonymisation frameworks remain gaps pending legislative reform.

Sub-modules (4)

Lawful BasesGreen

PIPA authorizes collection, use and disclosure only for purposes a reasonable person would consider appropriate in the circumstances.

Claims: CLM-CA-AB-f6a7b8c9

Special CategoriesRed

PIPA has no defined category of 'sensitive personal information'; the OIPC and Alberta's Ministry of Technology and Innovation have proposed adding one covering biometric, children's and intimate information.

Claims: CLM-CA-AB-c9d0e1f2

Pseudonymisation And AnonymisationRed

PIPA lacks a statutory de-identification/anonymisation framework; the OIPC has recommended one including definitions, standards and re-identification prohibitions.

Claims: CLM-CA-AB-d0e1f2a3

Category narrative59 words

PIPA uses a 'reasonable purpose' standard rather than an enumerated lawful-bases list, and its consent regime centres on knowledgeable, reasonably-understandable notice, with a distinct carve-out for 'personal employee information'. PIPA currently has no statutory definition of 'sensitive/special category' information or a codified de-identification/anonymisation framework; both are subjects of active reform recommendations from the OIPC and the federal Privacy Commissioner.

Sources and claims (5)
  1. ConfirmedOffice of the Privacy Commissioner of CanadaAn organization may collect, use or disclose personal information under PIPA only for a purpose that a reasonable person would consider appropriate in the circumstances.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaPIPA currently requires organizations to provide notice, in a form the individual can reasonably be considered to understand, of intended collection, use or disclosure purposes.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaPIPA permits organizations to collect 'personal employee information' without consent where reasonable for establishing, managing or terminating an employment or volunteer relationship.
  4. ProbableOffice of the Privacy Commissioner of CanadaPIPA does not currently contain a defined category of sensitive personal information; the OIPC and Alberta's Ministry of Technology and Innovation have recommended creating one covering biometric, children's and intimate information.
  5. ProbableOffice of the Privacy Commissioner of CanadaPIPA lacks a codified framework for de-identified or anonymized information; the OIPC has recommended one including definitions, standards, and prohibitions on re-identification.

#

Access rights are established and in force; portability is aspirational/reform-stage only, and precise deadline figures require primary-source verification.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberAccess rights are established and in force; portability is aspirational/reform-stage only, and precise deadline figures require primary-source verification.

Sub-modules (5)

Access RightGreen

PIPA provides individuals the right to access personal information held by an organization.

Claims: CLM-CA-AB-e1f2a3b4

Rectification And ErasureAmber

PIPA imposes correction-related obligations on organizations as part of its access framework; OIPC review materials reference a 'right to erasure' as a reform topic under discussion, implying no fully codified erasure right yet.

Claims: CLM-CA-AB-f2a3b4c5

Restriction And ObjectionRed

No explicit standalone restriction/objection right distinct from access/correction was confirmed in sources reviewed for PIPA.

Absence provenance: not recorded. Searched: Alberta PIPA right to restrict processing, Alberta PIPA right to object profiling.

Data PortabilityRed

PIPA does not currently include a data portability right; the OIPC has called for amendment to add a 'right to portability and data mobility'.

Claims: CLM-CA-AB-a3b4c5d6

Deadlines And Response WindowsAmber

Specific statutory day-count deadlines for PIPA access-request responses were not independently confirmed in the sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA access request response deadline days, PIPA section 28 response time.

Category narrative48 words

PIPA grants individuals a right of access to personal information held by organizations and corresponding correction rights, but currently lacks a codified data-portability right; the OIPC has called for one modeled on the federal CPPA's data-mobility provisions. Specific statutory response-window day-counts were not confirmed in the sources reviewed.

Sources and claims (3)
  1. ConfirmedDataGuidancePIPA provides individuals the right to access personal data held about them by an organization.
  2. UncertainOffice of the Privacy Commissioner of CanadaA codified 'right to erasure' under PIPA remains a reform-discussion topic rather than a confirmed existing statutory right, per the Alberta Legislative Assembly's PIPA review materials.
  3. ProbableOffice of the Privacy Commissioner of CanadaThe Alberta OIPC has called for PIPA to be amended to include a right to portability and data mobility, allowing individuals to obtain or transfer their personal information in a structured, machine-readable format.

#

Breach notification and accountability-for-transfers are in force and well-precedented, but DPIA/DPO/ROPA/AMPs infrastructure is thin relative to GDPR-style regimes.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberBreach notification and accountability-for-transfers are in force and well-precedented, but DPIA/DPO/ROPA/AMPs infrastructure is thin relative to GDPR-style regimes.

Sub-modules (7)

Accountability And DpiaAmber

OIPC comments on PIAs submitted by organizations; PIPA does not mandate PIAs across the board as a statutory requirement, unlike POPA's public-sector PIA mandate.

Claims: CLM-CA-AB-b4c5d6e7

Dpo RequirementsAmber

No explicit statutory DPO-appointment threshold under PIPA was confirmed; organizations commonly designate an informal 'privacy officer' as a practice matter.

Absence provenance: not recorded. Searched: Alberta PIPA DPO appointment requirement, PIPA privacy officer designation threshold.

Ropa RequirementsRed

No explicit records-of-processing-activities (ROPA) requirement under PIPA was identified in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA records of processing requirement.

Joint Controller ArrangementsGreen

An organization that transfers personal information to a third party for processing remains responsible for that information under PIPA-aligned accountability guidance.

Claims: CLM-CA-AB-c5d6e7f8

Security MeasuresAmber

General security-of-processing obligations exist under PIPA's accountability principle; specific technical/organisational measure requirements were not independently itemized in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA security safeguard requirements detail.

Breach NotificationGreen

PIPA requires organizations to notify the OIPC without unreasonable delay of breaches posing a real risk of significant harm (RROSH); Alberta was the first Canadian jurisdiction (2010) to mandate private-sector breach notification. The Health Information Act imposes a parallel harm-based breach-notification regime for custodians.

Claims: CLM-CA-AB-d6e7f8a9, CLM-CA-AB-e7f8a9b0, CLM-CA-AB-f8a9b0c1

Retention And DisposalAmber

No specific statutory retention-period figures under PIPA were confirmed in sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA retention period requirement, PIPA disposal of personal information duty.

Category narrative72 words

PIPA imposes accountability for personal information transferred to third parties for processing, and a mandatory breach-notification duty to the OIPC where a real risk of significant harm (RROSH) exists — Alberta was the first Canadian jurisdiction to adopt breach notification (2010). PIPA currently lacks an administrative monetary penalties (AMPs) regime, a codified ROPA requirement, or an explicit DPO-designation threshold; these remain gap areas versus the federal CPPA proposal and Quebec's Law 25.

Sources and claims (5)
  1. ProbableDataGuidanceThe OIPC's powers include commenting on the implications of Privacy Impact Assessments sent to it, though PIPA does not impose a blanket statutory PIA mandate on all organizations.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaUnder joint OPC/Alberta/BC accountability guidance, the law stipulates that an organization transferring personal information to a third party for processing remains responsible for that information.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaPIPA requires organizations that suffer a privacy breach to notify the OIPC without unreasonable delay where the breach poses a real risk of significant harm to affected individuals, and the Commissioner may then require notification of affected individuals.
  4. ConfirmedIAPPAlberta became the first Canadian jurisdiction to implement mandatory breach notification in private-sector privacy legislation, in 2010.
  5. ConfirmedIAPPThe Health Information Act requires custodians to notify affected individuals, the Minister of Health, and the OIPC of privacy breaches meeting a harm-based risk threshold, following a structured risk-of-harm analysis.

#

Adequacy inheritance via PIPEDA is confirmed and strong, but Alberta-specific transfer mechanisms (SCCs, TIAs, localisation) are not independently codified.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA); Personal Information Protection and Electronic Documents Act (PIPEDA) for trans-border flows
Traffic-light rationale — AmberAdequacy inheritance via PIPEDA is confirmed and strong, but Alberta-specific transfer mechanisms (SCCs, TIAs, localisation) are not independently codified.

Sub-modules (6)

Transfer MechanismsGreen

When Alberta organizations subject to PIPA engage in trans-border personal information flows for commercial reasons, they must follow PIPEDA for those specific transactions.

Claims: CLM-CA-AB-a9b0c1d2

Adequacy ReceivedGreen

Canada's PIPEDA-based regime (which governs Alberta organizations' international transfers) continues to be found adequate by the European Commission.

Claims: CLM-CA-AB-b0c1d2e3

Adequacy GrantedAmber

No evidence was found of Alberta or Canada granting outbound adequacy-style determinations to other regimes; Canada's model is organization-accountability based rather than state-to-state adequacy granting.

Claims: CLM-CA-AB-c1d2e3f4

Sccs And BcrsAmber

No Alberta-specific SCC or BCR mechanism was identified; PIPEDA's accountability principle (Schedule 1, Principle 1) governs outsourcing/transfer arrangements instead of a formal contractual-clause regime.

Claims: CLM-CA-AB-c1d2e3f4

Transfer Impact AssessmentRed

No standalone Transfer Impact Assessment requirement analogous to GDPR Schrems II practice was identified for PIPA-covered organizations.

Absence provenance: not recorded. Searched: Alberta PIPA transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate for Alberta's private sector was identified in sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA data residency requirement, Alberta private sector data localisation mandate.

Category narrative69 words

PIPA-covered organizations must additionally comply with PIPEDA for trans-border commercial data flows, since Alberta's substantially-similar status only displaces PIPEDA for intra-provincial activity. Canada (and therefore the PIPEDA layer applicable to Alberta organizations' international transfers) retains its EU adequacy status as reaffirmed in the European Commission's most recent review. No SCC/BCR-style formal transfer-mechanism regime or data-localisation mandate specific to Alberta's private sector was identified; the accountability-based (organization-to-organization) model applies instead.

Sources and claims (3)
  1. ConfirmedOffice of the Privacy Commissioner of CanadaWhen Alberta organizations subject to PIPA engage in trans-border personal information flows for commercial reasons, they must follow PIPEDA for those specific transactions.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaCanada's adequacy status under the EU GDPR was reviewed, with the European Commission finding that Canada continues to provide an adequate level of protection for personal information transferred from the EU to recipients subject to PIPEDA.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaPIPEDA does not prohibit transferring personal information to another jurisdiction for processing but instead governs such transfers through an organization-accountability model rather than adequacy or standard-contractual-clause designations.

#

Health-sector overlay is robust and well-evidenced; employment carve-out is confirmed; financial/credit/insurance/telecoms overlays are evidentiary gaps.

Primary frameworkHealth Information Act, RSA 2000, c H-5 (health sector); PIPA (employment carve-out)
Traffic-light rationale — AmberHealth-sector overlay is robust and well-evidenced; employment carve-out is confirmed; financial/credit/insurance/telecoms overlays are evidentiary gaps.

Sub-modules (7)

Financial Sector OverlayRed

No Alberta-specific financial-sector DP overlay was confirmed in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA financial sector overlay, Alberta banking privacy overlay.

Health Sector OverlayGreen

The Health Information Act imposes mandatory, harm-triggered breach notification on custodians, with tiered offence fines for custodians and affiliates who fail to report.

Claims: CLM-CA-AB-d2e3f4a5, CLM-CA-AB-e3f4a5b6

Telecoms And EprivacyRed

No Alberta-specific telecoms/ePrivacy overlay distinct from general PIPA/PIPEDA consent principles was confirmed in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA telecoms overlay, Canada ePrivacy cookie law Alberta.

Employment DataGreen

PIPA carves out 'personal employee information' from standard consent requirements where collection is reasonable for managing the employment relationship.

Claims: CLM-CA-AB-f4a5b6c7

Credit And ScoringAmber

No Alberta-specific credit-scoring overlay was confirmed; general PIPEDA/PIPA principles apply to inter-provincial credit-bureau data flows as a trans-border-flow example.

Absence provenance: not recorded. Searched: Alberta PIPA credit scoring regulation, Alberta credit reporting privacy overlay.

EducationAmber

Alberta schools using the PowerSchool Student Information System generated 31 breach notices to the OIPC following a cyberattack affecting 5.2 million Canadians.

Claims: CLM-CA-AB-a5b6c7d8

InsuranceRed

No Alberta-specific insurance-sector DP overlay was confirmed in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA insurance sector overlay.

Category narrative66 words

Alberta's health sector is governed by a distinct Health Information Act (HIA) regime with harm-based breach notification and tiered offence penalties, layered atop PIPA/PIPEDA. PIPA itself carves out 'personal employee information' from ordinary consent rules. Education-sector incidents (e.g., the PowerSchool breach affecting Alberta schools) have driven OIPC breach-notice activity. No material Alberta-specific overlays for financial services, credit-scoring, or insurance were confirmed in sources reviewed this run.

Sources and claims (4)
  1. ConfirmedIAPPThe Health Information Act requires custodians to notify affected individuals, the Minister of Health and the OIPC of certain privacy breaches that could create a risk of harm, subject to a harm-based trigger and prescribed safe harbours.
  2. ConfirmedIAPPUnder HIA regulations, individual custodians who fail to comply with breach obligations face fines between $2,000 and $10,000, while organizational custodians face fines between $200,000 and $500,000.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaPIPA allows organizations to collect 'personal employee information' without consent where reasonable for establishing, managing, or terminating an employment or volunteer relationship.
  4. ConfirmedDataGuidanceA cyberattack on PowerSchool's Student Information System affected 5.2 million Canadians and generated 31 breach notices from Alberta schools reported to the OIPC.

#

This module carries an explicit evidentiary gap; Alberta has no adtech-specific statute distinct from PIPA's general consent regime.

Traffic-light rationale — RedThis module carries an explicit evidentiary gap; Alberta has no adtech-specific statute distinct from PIPA's general consent regime.

Sub-modules (6)

Cookies And TrackersRed

No Alberta-specific cookie/tracker consent statute was identified.

Absence provenance: not recorded. Searched: Alberta PIPA cookies tracker consent regulation.

Dark PatternsRed

No Alberta-specific dark-pattern prohibition was identified.

Absence provenance: not recorded. Searched: Alberta PIPA dark patterns prohibition.

Opt Out SignalsRed

No Alberta-specific recognition of Global Privacy Control or similar opt-out signals was identified.

Absence provenance: not recorded. Searched: Alberta PIPA Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Alberta-specific clean-room/data-collaboration-room rules were identified.

Absence provenance: not recorded. Searched: Alberta PIPA clean room data collaboration rules.

Cross Context AdvertisingRed

No Alberta-specific 'sale'/'share' cross-context advertising framework analogous to US state law was identified.

Absence provenance: not recorded. Searched: Alberta PIPA cross-context advertising sale share.

Direct MarketingAmber

No Alberta PIPA-specific direct-marketing consent/suppression regime distinct from general consent principles was identified; Canada's federal anti-spam law (CASL) may apply but was outside the scope confirmed this run.

Absence provenance: not recorded. Searched: Alberta PIPA direct marketing consent rules.

Category narrative50 words

No Alberta-specific statutory regime for cookies/trackers, dark patterns, opt-out signals, clean rooms, cross-context advertising, or direct marketing was identified in the sources reviewed this run; general PIPA consent/purpose principles would apply by extension, but no dedicated adtech rules, GPC-equivalent recognition, or 'sale'/'share' framework analogous to US state laws were found.

#

Strong enforcement precedent on biometrics exists, but no codified statutory ADM-transparency or profiling-restriction provision was confirmed; AI-specific rules are emergent/sector-limited (health).

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA); Health Information Act (AI-in-healthcare overlay)
Traffic-light rationale — AmberStrong enforcement precedent on biometrics exists, but no codified statutory ADM-transparency or profiling-restriction provision was confirmed; AI-specific rules are emergent/sector-limited (health).

Sub-modules (6)

Profiling RestrictionsRed

No standalone statutory profiling-restriction provision under PIPA was confirmed.

Absence provenance: not recorded. Searched: Alberta PIPA profiling restriction provision.

Automated Decision Making TransparencyRed

No standalone ADM-transparency/explanation right under PIPA was confirmed in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA automated decision-making transparency right.

Ai Risk AssessmentsAmber

OIPC has issued guidance for custodians completing PIAs for AI scribe tools under the HIA, and for small custodians on AI use generally; Bill 11 introduces HIA amendments addressing AI in healthcare.

Claims: CLM-CA-AB-b6c7d8e9, CLM-CA-AB-c7d8e9f0

Biometric RegimeAmber

Joint OIPC-Alberta/BC/federal/Quebec investigations found Clearview AI's image scraping constituted inappropriate mass biometric surveillance, and found that Cadillac Fairview's mall-kiosk facial-data collection required express consent that was not obtained.

Claims: CLM-CA-AB-d8e9f0a1, CLM-CA-AB-e9f0a1b2

Genetic DataAmber

The OIPC issued a public alert on privacy risks to Albertans' genetic data following 23andMe's asset sale to TTAM, emphasizing PIPA-based data protection obligations, though this is guidance rather than a distinct statutory genetic-data regime.

Claims: CLM-CA-AB-f0a1b2c3

State Surveillance CarveoutsRed

No specific Alberta PIPA state-surveillance/national-security carveout provision was confirmed in sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA national security exemption, PIPA state surveillance carveout.

Category narrative81 words

While PIPA has no dedicated statutory ADM-transparency or profiling-restriction provisions, the Alberta OIPC has been an active co-investigator in major biometric-privacy enforcement matters (Clearview AI, Cadillac Fairview facial-recognition kiosks), establishing strong precedent that express consent is required for biometric collection and that mass biometric scraping is an inappropriate purpose. Alberta is also actively regulating AI use in the health sector via HIA amendments (Bill 11) and OIPC PIA guidance for AI scribe tools, though this remains partly in a reform/rollout stage.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe OIPC of Alberta issued guidance for custodians on completing Privacy Impact Assessments for AI scribe tools under the Health Information Act.
  2. ProbableDataGuidanceBill 11 introduces amendments to Alberta's Health Information Act addressing privacy, accountability, and AI use in healthcare amid restructuring.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaA joint investigation by the federal, Alberta, British Columbia and Quebec privacy authorities found Clearview AI's scraping of images and creation of biometric facial-recognition arrays constituted inappropriate mass identification and surveillance of individuals.
  4. ConfirmedOffice of the Privacy Commissioner of CanadaA joint investigation with the Alberta and BC privacy commissioners found that Cadillac Fairview's collection of facial images and biometric data via mall directory kiosks required express consent that had not been validly obtained.
  5. ConfirmedDataGuidanceAlberta's OIPC alerted citizens to privacy risks following 23andMe's asset sale to TTAM, emphasizing data protection obligations under PIPA for genetic information.

#

Age-of-majority baseline is confirmed, but dedicated minor-specific consent/profiling provisions in PIPA are absent or reform-stage only.

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberAge-of-majority baseline is confirmed, but dedicated minor-specific consent/profiling provisions in PIPA are absent or reform-stage only.

Sub-modules (5)

Age VerificationAmber

Alberta's age of majority is 18; no PIPA-specific age-verification mandate for data processing was identified.

Claims: CLM-CA-AB-a1b2c3d5

Minor Profiling BansRed

No PIPA-specific minor-profiling ban was identified; children's information has only been proposed as a sensitive-category addition.

Claims: CLM-CA-AB-b2c3d5e6

Education SettingsAmber

Alberta schools using the PowerSchool Student Information System generated 31 breach notices to the OIPC involving unauthorized access to students' personal information.

Claims: CLM-CA-AB-c3d5e6f7

Dependent AdultsRed

No Alberta PIPA-specific dependent-adult/vulnerable-adult data protection provision was identified in sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA dependent adult data protection provision.

Category narrative56 words

Alberta's age of majority is 18, but PIPA does not have a distinct statutory consent-age threshold or parental-consent mechanism separate from its general reasonable-person standard; children's information has been proposed (not yet enacted) as a category of sensitive information. Education-sector incidents (PowerSchool breach) have directly implicated minors' data. No dependent-adults-specific provisions were confirmed in sources reviewed.

Sources and claims (3)
  1. ConfirmedOffice of the Privacy Commissioner of CanadaThe age of majority in Alberta is 18, as referenced in federal breach-reporting guidance distinguishing provincial age-of-majority thresholds.
  2. ProbableOffice of the Privacy Commissioner of CanadaAlberta's Ministry of Technology and Innovation proposed that PIPA create a specific category of sensitive personal information including children's information, though this has not been enacted.
  3. ConfirmedDataGuidanceThe OIPC reported 31 breach notices from Alberta schools using the PowerSchool Student Information System, involving unauthorized access to students' personal information.

#

Strong order-making and offence provisions are in force with active joint enforcement, but the absence of an AMPs regime is a material capability gap relative to peer regimes (Quebec, EU, UK).

Primary frameworkPersonal Information Protection Act, SA 2003, c P-6.5 (PIPA)
Traffic-light rationale — AmberStrong order-making and offence provisions are in force with active joint enforcement, but the absence of an AMPs regime is a material capability gap relative to peer regimes (Quebec, EU, UK).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

OIPC has binding order-making powers under PIPA not subject to appeal to an external tribunal, and PIPA creates an offence for wilfully attempting to gain unauthorized access to personal information.

Claims: CLM-CA-AB-d5e6f7a8, CLM-CA-AB-e6f7a8b9

Enforcement Activity IndexGreen

The OIPC has been active in joint investigations (Clearview AI, Cambridge Analytica/Facebook, Tim Hortons, TikTok, OpenAI, tenant-screening/background-check services) alongside the federal OPC, BC and Quebec regulators.

Claims: CLM-CA-AB-f7a8b9c0

Regulator Funding And CapacityAmber

No specific OIPC Alberta headcount or budget figures were confirmed in sources reviewed this run.

Absence provenance: not recorded. Searched: OIPC Alberta budget headcount capacity 2026.

Collective Redress And Class ActionsAmber

No PIPA-specific collective-redress or class-action mechanism was confirmed distinct from general Alberta civil procedure in sources reviewed.

Absence provenance: not recorded. Searched: Alberta PIPA class action privacy breach.

Private Right Of ActionAmber

No explicit PIPA private-right-of-action provision distinct from OIPC complaint/order processes was confirmed in sources reviewed this run.

Absence provenance: not recorded. Searched: Alberta PIPA private right of action court damages.

Recent Developments 180DGreen

Public-body privacy-management-program obligations under POPA took full effect June 11, 2026 (end of a one-year grace period), and a new mandatory PIA template for public bodies under POPA started May 1, 2026.

Claims: CLM-CA-AB-a8b9c0d1, CLM-CA-AB-b9c0d1e2

Category narrative106 words

The OIPC holds binding order-making powers under PIPA (s.52-equivalent authority), not subject to appeal to an external tribunal (only judicial review), and PIPA creates offences including wilfully attempting to gain unauthorized access to personal information (s.59(1)). Alberta's PIPA, like PIPEDA, currently lacks an administrative monetary penalties (AMPs) regime — Quebec's CAI remains the only Canadian privacy regulator with AMP powers. The OIPC is an active participant in joint multi-jurisdictional investigations (Clearview AI, Cambridge Analytica/Facebook, Tim Hortons, TikTok, OpenAI, tenant-screening/background-check services). Recent developments include the POPA privacy-management-program mandate taking full effect June 11, 2026, and a new mandatory PIA template for public bodies from May 1, 2026.

Sources and claims (5)
  1. ConfirmedOffice of the Privacy Commissioner of CanadaUnlike the federal OPC's orders under the proposed CPPA, the Alberta OIPC's orders are not subject to appeal by an external tribunal, only to judicial review by a court.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaSection 59(1) of Alberta's PIPA makes it an offence to wilfully attempt to gain or gain access to personal information in contravention of the Act.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaThe federal Privacy Commissioner conducts joint investigations with the Alberta OIPC and other provincial counterparts, including cases such as Clearview AI, Facebook/Cambridge Analytica, Tim Hortons, OpenAI, TikTok, and an ongoing tenant-screening/background-check services investigation.
  4. ConfirmedIAPPPublic bodies in Alberta are required to implement a privacy management program by June 11, 2026, when the one-year grace period under the Protection of Privacy Act expires.
  5. ConfirmedDataGuidanceAlberta's OIPC mandated a new Privacy Impact Assessment template for public bodies to standardize compliance with POPA starting May 1, 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada – Alberta
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s), 18 source(s) in the cumulative register.