A Calgary accounting firm gets hit with a ransomware attack on a Friday afternoon. By Monday, the IT team has contained it, restored from backup, and everyone breathes out. Then someone asks the obvious question: do we have to report this to anyone? The instinct is to search for PIPEDA breach requirements, because that’s the federal law everyone’s heard of. But if that firm collects, uses, or discloses personal information entirely within Alberta, PIPEDA likely isn’t the law that governs them at all. Alberta’s Personal Information Protection Act, PIPA, is. And PIPA has its own reporting threshold, its own regulator, its own timeline, and its own penalties, all of which are frequently confused with the federal rules or missed entirely.
This matters because the two laws don’t always overlap the way business owners assume. PIPA applies to organizations, corporations, partnerships, trade unions, and individuals acting in a commercial capacity, that collect, use, or disclose personal information in the course of commercial activity within Alberta. PIPEDA generally governs federally regulated businesses and organizations engaged in interprovincial or international commercial activity. A Calgary-based dental practice, law firm, or oil and gas contractor whose business is conducted within the province is typically operating under PIPA, not PIPEDA, even though nearly every generic breach-response article written for a Canadian audience defaults to the federal framework.
The Trigger Isn’t “Did Data Leak.” It’s “Real Risk of Significant Harm”
PIPA doesn’t require an organization to report every incident where personal information was touched. According to the Office of the Information and Privacy Commissioner of Alberta, the legal threshold is narrower and more specific: a “real risk of significant harm,” known in practice as RROSH. Under section 34.1 of PIPA, an organization must notify the OIPC where a reasonable person would consider that a real risk of significant harm exists to an individual as a result of the loss, unauthorized access, or unauthorized disclosure of their personal information, and that notification must happen without unreasonable delay.
RROSH is a two-part test. There has to be an actual, non-speculative risk, and the harm that could follow has to be significant: financial loss, identity theft, damage to reputation, not merely inconvenience. This is a judgment call, and Alberta’s regulator has built a substantial record to guide it. As Miller Thomson’s analysis of the OIPC’s decade-long breach report found, of the 1,953 breach reports the OIPC received between 2010 and 2022, 68% were found to meet the RROSH threshold, and that rate climbed to 70-80% for reports filed between 2017 and 2022, up from under half in the law’s earlier years. This tracks with what every managed IT provider in Calgary already sees in the field: 71% of RROSH-qualifying breaches involved deliberate, malicious action rather than accidental exposure, with ransomware and system compromises chief among them. If your incident involved an attacker rather than a misdirected email, the odds it clears the reporting threshold are high.
Reporting to the Commissioner Is Mandatory. Notifying People Isn’t Automatic.
This detail trips up most businesses because it runs opposite to how the federal law works in the public imagination. Under PIPA, once RROSH exists, the organization must report to the OIPC. The statute does not automatically require notifying affected individuals directly. Instead, section 37.1 of PIPA gives the Commissioner the authority to review the breach report and issue a decision requiring the organization to notify affected individuals where warranted.
In practice, this distinction matters less than it should, because most organizations notify people on their own regardless of whether the Commissioner orders it. Since 2012-2013, at least 80% of organizations had already notified affected individuals by the time they reported the breach to the Commissioner. Waiting for a regulatory order before telling your clients or patients their data was exposed is both a reputational risk and, in most cases, not how responsible organizations actually behave. If you choose to notify people directly, that notification has to meet the minimum content requirements set out in section 19.1 of the PIPA Regulation, which requires the notice to include the name and contact information of someone at the organization who can answer questions about the breach, along with a description of the breach, when it occurred, and what steps are being taken in response.
What Actually Has to Be in the Report
The OIPC doesn’t accept phone calls or email summaries. Alberta uses a standardized PIPA Breach Notification Form, and the office updated its intake process and guidance in April 2024. The report needs to lay out the circumstances of the breach, the personal information involved, the number of individuals affected, the steps taken to contain it, and the organization’s assessment of whether RROSH exists and why. This is where a lot of businesses without a documented incident response process struggle, not because the requirements are unreasonable, but because reconstructing a clear timeline and RROSH analysis after the fact, under pressure, with a regulator waiting, is a bad time to be building that process for the first time.
The Penalties Aren’t Symbolic
Failing to report a reportable breach is an offence under PIPA, not just a compliance gap. According to the Government of Alberta’s guidance for organizations, section 59(2) sets fines of up to $10,000 for an individual and up to $100,000 for an organization found to have contravened the Act. These cases go through Alberta’s provincial court following a referral from the Commissioner to the Crown, not an administrative penalty issued directly by the OIPC, but the exposure is real, and it sits on top of whatever direct costs the breach itself already caused.
It’s also worth knowing that this framework is under active reform. Alberta’s Standing Committee on Resource Stewardship completed a mandatory legislative review and recommended, among other changes, that the penalty ceiling be raised to align with comparable Canadian privacy legislation. No amendment bill has been introduced as of this writing, but the direction is clear enough that businesses building a compliance posture now shouldn’t assume today’s numbers are permanent.
Where This Actually Gets Decided: Before the Breach, Not After
The organizations that handle this well aren’t the ones with the best lawyer on retainer. They’re the ones who already know, before an incident happens, what systems hold personal information, who gets notified internally the moment something looks wrong, and how quickly they can produce a clear timeline of what was accessed and when. RROSH determinations depend on specifics: what type of information was involved, whether access was confirmed or merely possible, whether the actor’s intent was malicious. An organization that can answer those questions within hours is in a fundamentally different position than one still trying to figure out what happened a week later.
That’s also where the connection between privacy compliance and day-to-day IT management becomes obvious. Endpoint monitoring, logging, and a documented incident response plan aren’t just security hygiene, they’re the evidence base a RROSH determination and a breach report actually rely on. Our cybersecurity services for Calgary businesses are built around exactly this: risk assessments, monitoring, and incident response planning that give you the documentation and the timeline you need if you ever have to answer the question this article opened with.
If you’re not sure whether your current IT setup would let you reconstruct a breach timeline fast enough to meet PIPA’s “without unreasonable delay” standard, that’s worth finding out before an incident forces the answer. Pure IT provides managed IT services across Calgary and Southern Alberta, and a complimentary IT review is a reasonable place to start if breach readiness has been sitting on the to-do list longer than it should.
