New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Alberta & BC Private-Sector Privacy
PIPA Compliance in Alberta & British Columbia
Alberta and British Columbia each have their own Personal Information Protection Act. If you operate in either province, PIPA — not PIPEDA — sets the rules for the personal information you collect. We help you build one program that satisfies both Commissioners.
The Basics
What PIPA is and who it applies to
PIPA is the name of two separate provincial laws: Alberta’s Personal Information Protection Act, overseen by the Office of the Information and Privacy Commissioner of Alberta, and British Columbia’s Personal Information Protection Act, overseen by the OIPC of British Columbia. Both have been in force since 2004, and both are deemed substantially similar to the federalPIPEDA — which is why they, rather than PIPEDA, govern personal information handled within each province.
The Acts apply to private-sector organizations — corporations, partnerships, professional practices and, in BC, non-profits and other unincorporated bodies. A distinctive feature of both laws is a dedicated set of rules for employee personal information, which lets employers collect, use and disclose what is reasonably needed to manage the employment relationship, with notice rather than consent in many cases.
Cross-border and inter-provincial flows still fall under PIPEDA, so most organizations with customers outside their home province live under two regimes at once. Our overview ofthe Canadian privacy law landscapeshows how the pieces fit, andDoes PIPEDA apply to my business?walks through the federal side of the question.
Alberta PIPA
Alberta’s Personal Information Protection Act, overseen by the Office of the Information and Privacy Commissioner of Alberta. In force since 2004; the first Canadian law with mandatory breach notification.
British Columbia PIPA
BC’s Personal Information Protection Act, overseen by the OIPC of British Columbia. In force since 2004 and unusual in reaching non-profits and other unincorporated organizations.
Employee Personal Information
Both Acts contain dedicated rules for the information employers collect to manage the employment relationship — often with notice rather than consent.
Where PIPEDA Still Applies
Cross-border and inter-provincial flows, and federally regulated businesses, remain under PIPEDA, so most organizations live under two regimes at once.
Key Requirements
What PIPA requires of an organization

Reasonable purposes and consent
Collect, use and disclose personal information only for purposes a reasonable person would consider appropriate, with consent — express, implied or opt-out where permitted — and a clear explanation of purposes at or before collection.
An accountable privacy officer and written policies
Designate someone responsible for compliance, and develop policies and practices — available on request — that explain how you handle personal information and how complaints are dealt with.
Employee personal information rules
Apply the employment-specific provisions: collection limited to what is reasonable for the employment relationship, with notice to employees of purposes before or at collection.
Access and correction
Give individuals access to their personal information and correct it on request, within the statutory deadline — which differs between the two Acts — and with the exceptions each Act allows.
Safeguards and retention limits
Protect personal information with reasonable security arrangements, keep it only as long as the purpose or the law requires, and then destroy or anonymize it.
Service providers outside Canada
Alberta requires notice to individuals when their information is transferred to a service provider outside Canada, and both Acts keep you accountable for information in a provider’s hands.
Breach notification
In Alberta, breaches with a real risk of significant harm must be reported to the Commissioner, who can require notification of individuals. BC’s PIPA has no mandatory requirement in force yet, so follow OIPC BC guidance and PIPEDA-level practice.
Our Services
Our PIPA compliance services
One privacy management program designed to satisfy Alberta PIPA, BC PIPA and PIPEDA at the same time.
Gap Assessment Against Both Acts
A side-by-side review of your practices against Alberta PIPA, BC PIPA and PIPEDA, so one program satisfies every regulator you answer to.
Consent & Notice Design
Consent language, privacy notices and purpose statements that stand up to a reasonable-person test and fit how you actually collect information.
Policy & Procedure Development
The written policies both Acts require, plus the operating procedures — retention schedules, access workflows, vendor rules — that make them real.
Employee Information Program
Notices, HR policies and system controls for employee personal information, from recruitment to offboarding.
Access Request Workflows
Efficient handling of access and correction requests within each Act’s time limits, including redaction and exception handling.
Breach Response & Training
A rehearsed incident plan with the Alberta reporting test built in, and training that keeps staff from becoming the breach.
Typical building blocks:policy development,custom training, aPrivacy Impact Assessmentfor new systems, and aVirtual Privacy Officerto own the program. Need the fastest credible baseline? Start withMinimum Viable Privacy.
Why It Matters
Why PIPA compliance matters
Beyond avoiding penalties, PIPA compliance shows clients, partners and employees that you handle their information deliberately — and gives you the documentation to prove it.
Avoid Orders and Fines
Both Commissioners investigate complaints, issue binding orders and publish findings. Offences under either Act carry fines of up to $10,000 for individuals and $100,000 for organizations.
Win Business Across Provinces
Customers, partners and procurement teams increasingly ask for evidence of privacy compliance. A documented program answers the questionnaire before it arrives.
Build Customer and Employee Trust
Clear, honest information handling is what people notice — and, in the employment context, what keeps HR data from becoming a complaint.
How We Work
From scope to a sustained program in four steps
Scope
Establish which Act — or Acts — apply to each activity, where personal and employee information flows, and which vendors hold it.
Assess
Measure policies, consent practices, safeguards, retention and breach readiness against both Acts and the Commissioners’ guidance.
Remediate
Fix gaps in priority order: privacy officer, policies, notices, employee rules, access workflow, vendor terms, breach plan.
Sustain
Annual reviews, training refreshes and a privacy officer on call, so the program keeps pace with your business and the regulators.
FAQ
PIPA compliance questions, answered
Short answers to what Alberta and BC organizations ask us most.
If you are a private-sector organization operating in Alberta or British Columbia, the provincial PIPA governs the personal information you collect, use and disclose within that province, because each Act has been declared substantially similar to PIPEDA. PIPEDA still applies to federally regulated businesses and to information that crosses provincial or national borders — so a BC company with Ontario customers, or an Alberta company using a US cloud provider, answers to both.
Unlike PIPEDA, which reaches employee information only in federally regulated workplaces, both PIPAs apply to employee personal information in the provincial private sector. They let employers collect, use and disclose information that is reasonable for establishing, managing or terminating the employment relationship, and in many cases require notice to the employee rather than consent. The trade-off is that the reasonableness limit is real, and Commissioners do enforce it.
In Alberta, yes: since 2010 an organization must notify the Commissioner without unreasonable delay of any loss of, or unauthorized access to or disclosure of, personal information where a reasonable person would consider there is a real risk of significant harm, and the Commissioner can require you to notify the affected individuals. British Columbia’s PIPA does not yet have a mandatory breach-notification requirement in force, so BC organizations should follow OIPC BC guidance and PIPEDA-level practice — and remember that PIPEDA’s reporting rules can apply to the same incident if the data crossed borders.
Committing an offence under either Act — for example, collecting personal information in contravention of the Act, obstructing the Commissioner or failing to comply with an order — can result in fines of up to $10,000 for an individual and $100,000 for an organization. In practice the larger costs are the investigation itself, the binding orders, the public findings, and the customer and employee relationships damaged along the way.
Yes. Both Acts require an organization to designate one or more individuals responsible for ensuring compliance, and to make that person’s contact information available on request. The role can be part-time or outsourced, but it has to exist, and it has to be someone who actually understands the Acts and your information flows. Many small and mid-sized organizations meet the requirement with a Virtual Privacy Officer.
Generally yes, with conditions. You remain accountable for personal information handled by a service provider anywhere, so you need contractual protections and reasonable assurance about the provider’s safeguards. Alberta additionally requires that individuals be notified when their information is collected or transferred to a service provider outside Canada, and that your policies describe those transfers. Because the transfer crosses a border, PIPEDA’s expectations apply as well.
Close, but not identical. Because both PIPAs are substantially similar to PIPEDA, a program built on PIPEDA’s fair information principles covers most of the ground. The provincial specifics still matter: employee-information rules, Alberta’s foreign-service-provider notice and breach reporting, BC’s reach into non-profits, and each Act’s own access-request timelines. We design one program that meets all three sets of rules rather than three programs.
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.