Skip to main content
Home · Standards · Alberta Personal Information Protection Act (PIPA)
Standard · Alberta PIPA

Alberta Personal Information Protection Act (PIPA)

Alberta's Personal Information Protection Act (PIPA, SA 2003, c. P-6.5) is the substantially-similar provincial private-sector privacy law that displaces PIPEDA for activities within Alberta. PIPA requirements for ITAD are similar to PIPEDA but with Alberta-specific notification obligations and Office of the Information and Privacy Commissioner (OIPC) of Alberta enforcement. Maxicom Canada engagements covering Alberta operations are structured to satisfy PIPA in admissible form.

Alberta PIPA scope and obligations

PIPA applies to organisations engaged in commercial activity in Alberta. ITAD-relevant obligations: collection-limited-to-purpose, use-limited-to-purpose, destruction-when-purpose-fulfilled, safeguards appropriate to sensitivity, mandatory breach notification.

Mandatory breach notification

PIPA requires notification to the Privacy Commissioner of Alberta where there is a real risk of significant harm. The notification timeline is "without unreasonable delay". ITAD-relevant breaches in scope.

Energy-sector engagement profile

Alberta hosts the head offices of Suncor, Cenovus, TC Energy, Enbridge — major energy-sector IT estates. Refresh cycles produce predictable retiring volumes: head-office IT on 4-5 year cycles, OT/IT separated retirement for plant-floor systems, ICS/SCADA hardware on longer cycles.

Provincial-government engagement profile

Alberta provincial-government IT, Alberta Health Services, the University of Alberta system. Federation-of-public-sector-bodies procurement is the dominant pattern. Engagement model: programme-level master service agreements, witness destruction protocols.

Regulator stack — by region Every Maxicom certificate is admissible against the full stack simultaneously UNIVERSAL NIST SP 800-88 Rev. 1 · IEEE 2883-2022 · DoD 5220.22-M · NAID-grade Protocol 🇮🇳 INDIA INR · IST PRIVACY DPDPA 2023 BFSI RBI IT-Risk SECTOR-SPECIFIC SEBI · IRDAI · CERT-In · CPCB 🇨🇦 CANADA CAD · EST PRIVACY PIPEDA · Quebec Law 25 BFSI OSFI Guideline B-13 SECTOR-SPECIFIC PIPA (AB/BC) · PHIPA · ITSG-33 🇸🇬 SINGAPORE SGD · SGT PRIVACY PDPA Section 24 BFSI MAS TRM SECTOR-SPECIFIC IMDA · NEA Resource Sustainability Act 🇦🇪 UAE AED · GST PRIVACY UAE PDPL Article 21 BFSI Central Bank UAE SECTOR-SPECIFIC TDRA · DIFC DPL · ADGM · NESA
Reviewed by the Maxicom compliance desk. Last updated April 2026.
Operates to NIST 800-88 · PIPEDA · OSFI B-13 · NAID-grade · IEEE 2883-2022
References

Authoritative references

Primary sources for the standards and frameworks referenced on this page. Maxicom maps every engagement to these recognised authorities.

Frequently asked questions

Frequently asked questions

How does Alberta PIPA differ from PIPEDA?

Substantially similar but with Alberta-specific notification and OIPC enforcement. Maxicom certificates satisfy both simultaneously.

What about OT/IT separated retirement for energy-sector IT?

Standard in Alberta engagements. OT hardware (control systems, ICS, SCADA, PLC) sanitised per NIST SP 800-82 (industrial control system security); IT hardware per NIST SP 800-88. Per-asset certificates note the asset class.

When you are ready

Send the asset list. We will send the number.

A photograph of the rack works. A spreadsheet works better. CAD settlement, against PO.

purchase@maxicom.ca · per engagement SLA