If your Alberta business collects any personal information about customers or employees — names, emails, phone numbers, payment details — you're subject to a privacy law you may not have thought much about: the Personal Information Protection Act (PIPA). It's not just for big companies. Here's a plain-language overview and the practical IT safeguards that support compliance.
This is general information, not legal advice. For your specific obligations, consult a lawyer or your privacy advisor. Alberta's privacy laws are overseen by the Office of the Information and Privacy Commissioner of Alberta.
What PIPA is (and who it applies to)
PIPA is Alberta's private-sector privacy law. In broad terms, it governs how organizations collect, use, disclose, and protect the personal information of customers and employees. It applies to most Alberta businesses — not just large ones.
(Note: PIPA is the private-sector law. Alberta's public bodies, like municipalities, are covered by the newer POPA and ATIA that replaced FOIP in 2025 — a separate framework we cover here.)
The core principles, in plain terms
PIPA is built on common-sense ideas:
- Get consent. Collect personal information for reasonable purposes, with appropriate consent.
- Use it for what you said. Don't repurpose personal information beyond what people reasonably expect.
- Protect it. Make reasonable security arrangements to safeguard personal information against loss, theft, and unauthorized access.
- Be accountable. Have policies, and be prepared to respond to access requests and, where required, breaches.
The one with the biggest IT implications is protect it — and that's where most small businesses have gaps.
The IT safeguards that support compliance
"Reasonable security arrangements" isn't a checklist in the law, but in practice it means the same fundamentals that protect any business:
- Access controls. Individual accounts, strong passwords, and multi-factor authentication so only the right people reach personal information. See our MFA guide.
- Encryption. Protect data on laptops, devices, and in transit (email, file sharing).
- Endpoint and email protection. Stop the malware and phishing that lead to breaches.
- Backups. Verified, recoverable backups so a ransomware attack or failure doesn't destroy the data you're responsible for.
- Staff awareness. Your team handles this information daily — brief, regular training prevents most mistakes.
- A response plan. Know what you'd do if a breach happened.
Why it matters beyond the law
Even setting aside compliance, protecting customer data is good business. A breach means lost trust, potential legal exposure, and reputational damage that's hard to undo. The safeguards that keep you onside with PIPA are the same ones that keep your business resilient and your customers confident.
The bottom line
PIPA applies to most Alberta businesses, and its core requirement — make reasonable arrangements to protect personal information — comes down to the same security fundamentals every small business should have anyway: access controls, encryption, endpoint and email protection, backups, and staff awareness.
We help Alberta small businesses put those safeguards in place affordably. Learn more about our cybersecurity services, or book a free evaluation to see where you stand.
