Back to Research

WHEN, NOT IF // 04

When, Not IfAug 25, 202613 min

What Alberta Law Actually Requires the Day You Find Out

The day you find out, you may have three sets of legal obligations, not one — different thresholds, different clocks, different lists of who must be told. PIPA, PIPEDA and HIA mapped against each other from primary sources: who levies the fine (it isn't the Commissioner), and the 24-month breach log most Alberta operators attribute to the wrong statute.

WHEN, NOT IF #04 — T1 · LAW & LIABILITY. A series on what a breach actually costs in Canada. Previous episodes: Alberta doesn't require you to tell your customers · Your backup is a belief, not a system · The cheapest developer you ever hired.

The day you find out, you will not have one legal obligation. You may have three sets of them, with different thresholds, different clocks and three different lists of people who have to be told — and the law does not sort them for you. You sort them. In the first hours, using facts you probably don't have yet, while your systems are still down.

Plenty of Alberta businesses work this order of operations out on the worst day of their commercial life. It is written down, it is public, and it takes about fifteen minutes to read. Here is what it actually says.

First question: whose law is it?

Not "Canadian privacy law." There isn't one. There are several, and which one lands on you depends on what your company does and what kind of information moved.

Alberta's Personal Information Protection Act (PIPA) is the default for provincially regulated private-sector organizations operating in Alberta. It came into force January 1, 2004 and was last substantively amended in 2014 (Government of Alberta).

PIPEDA, the federal statute, is the one that reaches federally regulated works and undertakings — banking, telecommunications, air and interprovincial transport — and commercial activity that crosses a provincial or national border. Its breach obligations sit in Division 1.1, sections 10.1 to 10.3. Whether it reaches your particular operation is a scoping question for counsel, not a self-assessment: it is the single most common place where an organization concludes "provincial only" and turns out to have been wrong about the part that mattered.

Alberta's Health Information Act (HIA) applies to "custodians" holding individually identifying health information. The custodian list is broader than hospitals: physicians, pharmacists, dentists, chiropractors, optometrists, midwives, nursing homes and others, and it reaches their "affiliates" — a category the OIPC describes as including employees, volunteers, contractors and agencies under contract to a custodian, with the custodian ultimately responsible for what its affiliates do with the information (OIPC). If you contract to a clinic, the statute is in scope for the engagement whether or not your contract mentions it.

Two things follow that most operators get wrong.

The first: more than one regime can apply to the same incident. These statutes are scoped by who you are and what information moved, not by a rule that assigns each breach to exactly one of them — so a single incident can put you inside two sets of duties at once. Dual assessment belongs in the first hours, not the second week.

The second: "we're not an Alberta company" is not the test. The OIPC's guidance sets out when personal information counts as collected in Alberta — where the individual was in Alberta at the time of collection, and/or where the organization operates in Alberta. Its own worked example: an Albertan submits a job application to an Ontario company, stored on an Ontario server, and the information was still collected in Alberta (OIPC, Guidance for Notifying the Commissioner, April 2024).

And if a vendor was holding the data when it went: the same guidance separates custody from control. A contractor may have custody. The organization that sets the purposes, directs how the information is secured and can demand it back retains control — and control is what carries the duty to notify. Outsourcing the storage does not outsource the obligation.

Second question: does it clear the bar?

Under both PIPA and PIPEDA the trigger is the same phrase: real risk of significant harm — RROSH. Under HIA it is not, and that difference is covered further down. Two thresholds, three statutes — which is already one more than most incident-response plans account for.

PIPA s. 34.1 requires notice to the Commissioner where "a reasonable person would consider that there exists a real risk of significant harm to an individual as a result of the loss or unauthorized access or disclosure." PIPEDA s. 10.1(1) requires a report where "it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual" (Justice Canada, PIPEDA, current to 2026-06-17).

Significant is defined in the federal statute and it is wider than money: PIPEDA s. 10.1(7) provides that significant harm "includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property." Section 10.1(8) then lists the relevant factors — the sensitivity of the information, the probability that it has been, is being, or will be misused, and any other prescribed factor. Both provisions are drafted as inclusive lists, not closed ones.

Real risk has a floor. The OIPC is explicit that it "must be more than mere speculation or conjecture" and that there must be "a cause and effect relationship between the breach and the harm."

Then there is the line that should be pinned above every incident-response runbook in this province, because it is the one that turns a defensible file into an indefensible one:

Simply describing the risk of harm as being 'low', 'medium' or 'high' does not meet the requirement for an assessment of the risk of harm.

A colour-coded severity field in a ticketing system is not an assessment. The regulator has said so in writing, in advance. If your entire record of the most consequential judgment call in the incident is the word "medium," you have documented that you didn't do the work.

Note also the number the threshold does not contain. Both provisions are written in terms of a real risk of significant harm to an individual — singular. Nothing in that wording sets a minimum headcount below which the duty switches off. The Government of Alberta puts it in plain words: reporting a breach to the OIPC "is necessary even if only one individual is at risk" (Government of Alberta).

Third question: who has to be told — and this is where Alberta surprises people

Here the three regimes diverge sharply, and the gap is the single most misunderstood thing in Alberta breach response.

Under PIPA: the mandatory notice is to the Commissioner. It is the Commissioner who may then issue a decision requiring the organization to notify affected individuals (s. 37.1). Nothing prevents an organization from notifying people on its own initiative (s. 37.1(7)), and the Commissioner encourages exactly that — but the statutory duty runs to the regulator, not to your customer.

Under PIPEDA: notification to the affected individual is mandatory in its own right once the RROSH threshold is met (s. 10.1(3)), and s. 10.2(1) additionally requires notifying any other organization or government institution that may be able to reduce or mitigate the harm.

Under HIA: the trigger is lower and the list is longer. Section 60.1(2) requires a custodian to notify the Commissioner where there is "a risk of harm" — not real risk of significant harm, simply a risk of harm — and s. 60.1(3) requires the custodian to notify the Minister and the affected individuals as well (OIPC).

Three statutes, three different answers to "who do I have to call." The expensive version of this mistake runs one way in particular: an organization that is actually a custodian, applying the PIPA answer, would be measuring against a higher threshold than HIA sets while skipping two notifications HIA makes mandatory. Assessing against the stricter-sounding test does not protect you when the other statute's test is easier to meet and its notification list is longer.

One more figure, because it settles the argument that PIPA's narrow duty tends to start. The OIPC reports that since 2012–2013, at least 80% of organizations had already notified affected individuals by the time the breach was reported to the Commissioner. Voluntary notification isn't the cautious minority position in Alberta — it is what four out of five organizations already do. The Commissioner's published position is to encourage it: the guidance tells organizations not to wait for direction and to notify affected individuals on their own initiative where they believe a real risk of significant harm exists.

There is a condition attached to the generosity. Where an organization notifies on its own accord, the OIPC's position is that the notification contents should meet the minimum requirements of s. 19.1 of the PIPA Regulation. Choosing to notify does not let you choose the contents. A warm, vague, lawyer-free email to your customer list is not a safe way to discharge a standard you volunteered for.

The clock nobody can put a number on

PIPA: "without unreasonable delay." PIPEDA: "as soon as feasible." HIA: "as soon as practicable."

Three phrasings, zero deadlines. Operators consistently read this as slack. It is the opposite. A fixed 72-hour rule is a shield — meet it and you are compliant. An open standard is assessed after the fact, with hindsight, by someone reading your timeline backwards from the harm. The OIPC's own guidance asks organizations to explain any delay between discovering the breach and notifying, and recommends informing the Commissioner as soon as possible even if the internal investigation isn't finished.

Waiting until you have the full picture is not caution. Under this wording, it is the thing you will be asked to justify.

The record you are probably not keeping

This one gets missed in both directions — assumed where it doesn't apply, ignored where it does.

PIPEDA s. 10.3(1) requires an organization to keep and maintain a record of every breach of security safeguards — not only the reportable ones. The Breach of Security Safeguards Regulations set the retention period at 24 months after the day the organization determines the breach occurred, and require that the record contain enough information for the Commissioner to verify compliance (SOR/2018-64, s. 6).

Alberta's PIPA contains no equivalent standalone log requirement. Saying "we have to keep a breach log for two years under Alberta law" is wrong, and it's wrong in a way that signals you're reading a summary of a summary.

Keep the log anyway. Two reasons, both practical. If PIPEDA also touches your operation, it's mandatory. And if it doesn't, the log is still the best evidence you will ever have that the RROSH assessment happened, was reasonable, and was made on what you knew at the time. A regulator or a plaintiff can come asking two years after an incident you decided not to report. On that day, the log is the difference between a documented judgment call and an unprovable one.

Who actually fines you — and it isn't the Commissioner

PIPA s. 59(1)(e.1) makes it an offence to fail to notify the Commissioner of an incident meeting the s. 34.1 criteria. Where a person is found guilty, the fine is up to $10,000 for an individual and $100,000 for a person other than an individual (s. 59(2)) (OIPC, Guidance for Notifying the Commissioner, April 2024).

Read the mechanism, not the ceiling. That is an offence provision — it turns on a finding of guilt, not on an administrative penalty the regulator issues. The Commissioner investigates whether the s. 34.1 duty was met and can order an organization to notify affected individuals; the Commissioner does not levy that fine. The route runs through Crown prosecutors and a court.

The OIPC's own published record of an HIA prosecution shows the machinery in full. A former registration and staffing clerk pleaded guilty and was fined $3,000 in Athabasca Provincial Court. Alberta Health Services had identified 279 alleged unauthorized accesses; the OIPC investigated 28; for prosecution that number dropped to 21, because seven were barred by a two-year limitation period under HIA. The OIPC referred its findings to Crown prosecutors at Alberta Justice and charges were laid. It was the seventh conviction since HIA was enacted in 2001 (OIPC, April 19, 2017).

Two hundred seventy-nine alleged accesses. Seven counts lost to the clock. A $3,000 fine. And, as of that 2017 report, seven convictions in the sixteen years since HIA was enacted.

If your risk model treats the regulatory fine as the thing to be afraid of, that model is calibrated to the smallest number on the page. The real exposure is elsewhere: remediation, forensics, credit monitoring, business interruption, contractual liability to partners who required you to protect their data, and the customers who read about it before they heard from you.

What the courts have said, and what the same case shows costs money anyway

The Alberta decision everyone cites is Setoguchi v. Uber B.V. Certification was denied at 2021 ABQB 18 (January 8, 2021); the Court of Appeal dismissed the appeal at 2023 ABCA 45 (February 7, 2023); and the Supreme Court of Canada dismissed the application for leave, with costs, on July 13, 2023 (docket 40681) (SCC case information).

Two notes on weight, because this case gets stretched. A dismissal of leave is not a ruling on the merits — it means the Supreme Court declined to hear the appeal, not that it endorsed the reasoning below. And a certification decision turns on the specific record in front of the judge. What survives is an Alberta Court of Appeal decision that a proposed breach class action failed on that record, which is persuasive and useful — not a rule that breach class actions cannot succeed here.

Per the summary prepared by the Office of the Registrar of the SCC, the certification judge held that a class proceeding was not the preferable procedure because it was not clear that class-wide harm could be shown, and because proceeding as a class would not improve access to justice given that damages would be nominal at best.

That is genuinely favourable to defendants, and it is routinely over-read. It says that a breach without demonstrated loss is hard to certify in Alberta. It does not say a breach is free.

Look at what the record in that same case actually contains. The breach occurred in October 2016. A ransom was paid. The incident was disclosed in November 2017 — thirteen months later. The defendant was, in the Registrar's summary's words, subject to investigations and penalties worldwide, including in Canada. The class action failed. The thirteen months did not come free.

Read Setoguchi for what the defence actually rested on, and the exposure it leaves open becomes visible. Certification failed because class-wide harm was not clearly shown and damages looked nominal. Invert each of those and you get the conditions under which the same defence gets harder: information sensitive enough that harm is not speculative, and evidence that it was actually misused rather than merely exposed. Neither of those is decided by your lawyer. Both are decided by what you were holding and what happened to it.

Then there is the part that is entirely yours. Thirteen months elapsed between the breach and the disclosure in that case, and the class action still failed — but the regulatory investigations and penalties, in the Registrar's own summary, did not. Delay does not usually create the liability; it removes the best answer you had. "We responded promptly and documented it" is an argument you either can make on the day or cannot, and nothing you do later manufactures it.

The intrusion is the trigger. Your response is the part of the exposure you still control.

What changes Monday

Not a security project. Four documents, none of which require a purchase order.

One — write down which regimes apply to you, before anything happens. PIPA, PIPEDA, HIA, or a combination. One page, reviewed by counsel once. Determining this at 2 a.m. with your systems down is how the second mandatory notification gets missed.

Two — give the RROSH assessment a real form. Not a severity dropdown. The OIPC's guidance lists the questions it considers relevant, expressly as a non-exhaustive set: the nature of the information; who obtained or could have obtained access; how many people it was exposed to; whether there was any personal or professional relationship between the affected individual and the unauthorized recipient; whether security measures such as encryption were in place and whether they have known flaws; how long the information was exposed; whether there is evidence of malicious intent such as theft, hacking or malware; whether the information could be used for identity theft or fraud; whether it was recovered; how many individuals are affected; and whether any are vulnerable, such as youth or seniors. The regulator has published the questions in advance. Answering them on a blank page during an incident is a choice.

Three — start the breach log today, for every incident, including the ones you conclude are not reportable. Especially those. If PIPEDA reaches any part of your operation, the twenty-four-month record is mandatory rather than optional — and either way, two years from now the incident you decided not to report is the one you will need to prove you assessed.

Four — name the person who makes the call, and their backup. Every hour in the "who decides this" gap is an hour on a clock measured by the word "unreasonable."

None of this makes a breach less likely. All of it changes what the day after looks like — from a company reconstructing its own judgment under pressure, to a company executing a decision it already made.

One last thing: all three of these statutes are moving

Anything above that reads as settled should be read with its date attached, because two of the three regimes are mid-revision and the third is amended but not yet in force.

PIPEDA is the law in force today. Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts, received first reading on June 15, 2026 and is at second reading in the House of Commons, with no committee stage and no recorded votes (LEGISinfo). A bill at second reading is not law. Until it passes, s. 10.1 to 10.3 are what applies.

Alberta PIPA is under active review, with nothing enacted. The Standing Committee on Resource Stewardship completed its review in February 2025 with 12 recommendations; a public survey ran February 2–17, 2026; the responsible ministry is meeting the OIPC through Spring 2026; results are listed as under review and no amending bill has been introduced (Government of Alberta).

HIA has been amended, but the amendments are not in force. The Health Statutes Amendment Act, 2025 (No. 2) (Bill 11) received Royal Assent on December 11, 2025 and has not been proclaimed; the OIPC has written to the responsible ministers setting out concerns with the changes (OIPC).

Which is the strongest argument for the four documents above, not against them. The obligations will change. The requirement to have decided in advance who assesses, who is told, and where it gets written down will not.

The intrusion is not the event. What you do in the hours after it is the event — and that is the only part of this you can settle before it happens.


Want to know where your company actually stands? Eva will walk you through it — 15 minutes, no account, nothing stored: blackicelabs.ca/readiness

This is not legal advice. Breach obligations depend on your jurisdiction, sector and facts — get counsel.

#PrivacyLaw #AlbertaBusiness #DataBreach #Cybersecurity #RiskManagement

Written by Levon Azevedo

Get the next one by email.

Subscribe

Want to know where your company actually stands? Eva will walk you through it — 15 minutes, no account, nothing stored: blackicelabs.ca/readiness

This is not legal advice. Breach obligations depend on your jurisdiction, sector and facts — get counsel.