Data breach reporting in Alberta: PIPA, HIA and PIPEDA explained
This article is general information about Canadian privacy law as of October 2026. It is not legal advice. Confirm your obligations with legal counsel.
A ransomware attack or compromised mailbox is a technical emergency first. Within days, though, it becomes a legal question: do we have to report this, and to whom? In Alberta, the answer depends on which privacy law applies to you.
Which law applies to your organization?
| If you are… | The main law is… | Report to… |
|---|---|---|
| A private-sector business or non-profit operating in Alberta | Personal Information Protection Act (PIPA) | Office of the Information and Privacy Commissioner of Alberta |
| A health custodian, such as a physician, dental or pharmacy practice handling health information | Health Information Act (HIA) | The Commissioner, the Minister of Health, and affected individuals |
| A federally regulated business (bank, airline, telecom), or handling personal information across borders in commercial activity | PIPEDA (federal) | Office of the Privacy Commissioner of Canada, and affected individuals |
Some organizations fall under more than one law, for example a clinic that also handles non-health personal information, or a business whose data crosses provincial borders. Work this out with your counsel before an incident, not during one.
Alberta PIPA
Alberta’s PIPA has required breach notification since 2010, earlier than most of Canada. Under it, an organization must notify the Commissioner without unreasonable delay of any incident involving the loss of, or unauthorized access to or disclosure of, personal information under its control, where a reasonable person would consider that there is a real risk of significant harm to an individual.
The Commissioner can then require the organization to notify the affected individuals.
Health Information Act
Custodians under the HIA, which includes most health practitioners in Alberta, must notify the Commissioner, the Minister of Health and the affected individual when health information is accessed or disclosed without authorization and there is a risk of harm. They must also assess that risk using factors the Act sets out. For clinics and dental offices, a compromised practice-management system or email account is the typical scenario.
PIPEDA
Under the federal law, organizations must report breaches of security safeguards involving personal information that pose a real risk of significant harm to the Office of the Privacy Commissioner of Canada as soon as feasible, notify affected individuals, and notify any other organizations that can reduce the harm. Organizations must also keep a record of every breach for 24 months, including those that did not meet the reporting threshold.
The common thread: you need facts, fast
Every one of these tests depends on knowing what information was accessed, by whom, and whether it was taken. “We think they only encrypted the file server” is not enough to decide against notification.
That is why the first days of an incident should include:
- Containment. Stop the attacker’s access and prevent further data loss. See incident response.
- Evidence preservation. Logs, affected systems and any ransom communication. Do not wipe machines before they have been examined.
- Scoping. Which systems and accounts were accessed, which records they held, and whether there is evidence of data being copied out.
- A written record. A dated timeline of what happened and what you decided, and why. Regulators and insurers will ask for it.
- Counsel and insurer notified early. Many cyber policies include breach counsel and require prompt notice.
Prepare before it happens
- Know which law or laws apply to you, and who in your organization decides on notification.
- Know where your personal information lives, including email, file shares, cloud apps and backups.
- Make sure you have the logs to investigate. Many small businesses discover after a breach that Microsoft 365 audit logging was not retaining what they needed.
- Have an incident response provider and your insurer’s breach line on file. A vCISO can build the plan, and 24/7 MDR shortens the time between intrusion and detection.
If you are dealing with a suspected breach right now, call us. The number is at the top of this page.
Frequently asked questions
Does every data breach in Alberta have to be reported?
No. Under PIPA, notification to the Commissioner is required when a reasonable person would consider that there is a real risk of significant harm to individuals as a result of the loss of, or unauthorized access to or disclosure of, personal information. You should still document every incident and your assessment of it.
What counts as a 'real risk of significant harm'?
Regulators look at the sensitivity of the information, such as financial, health or identity data, and the probability that it will be misused, for example whether it was taken by a malicious actor or was encrypted. Ransomware with data theft usually meets the threshold. A lost encrypted laptop often does not.
Do we notify affected individuals directly?
Under PIPA, the Commissioner may require you to notify affected individuals. Under PIPEDA and the Health Information Act, notifying affected individuals is a direct obligation when the threshold is met. Many organizations also notify voluntarily so people can protect themselves.
Should we call our lawyer or our IT provider first?
Both, in the first hours. Your incident responders contain the attack and establish what data was accessed. Your legal counsel uses those facts to decide on notification. Call your cyber insurer early as well, because most policies require prompt notice and provide breach counsel.
How we can help
Incident Response
Ransomware or breach? Rapid containment plus a compromise assessment.
Learn more →vCISO Services
Senior security leadership, policy and risk management, part-time.
Learn more →Managed Detection & Response (MDR)
24/7 threat hunting and response by analysts who act, not just alert.
Learn more →