Privacy compliance for Alberta municipalities, worked from the Act itself.
On 11 June 2025 the privacy provisions of the FOIP Act were repealed and replaced by the Protection of Privacy Act. I work with villages, summer villages, towns and shared-administration offices on what that actually requires of them — and, more often, on what it doesn't.
- 11 June 2025
- POPA and the Access to Information Act came into force. The FOIP Act's privacy provisions were repealed the same day.
- 11 June 2026
- Privacy Management Programs required of every public body under POPA s.25 — no size threshold, no trigger test.
- 30 business days
- To give a copy of that programme to any person who asks, and to produce a PIA at the Commissioner's request.
One statute became two, and the obligations moved.
Access obligations went to the Access to Information Act. Privacy obligations went to the Protection of Privacy Act, with the detail set out in the Protection of Privacy (Ministerial) Regulation, AR 143/2025.
For a municipality this has a consequence that is easy to miss. Policies, consent wording, records schedules and website privacy statements written against FOIP now cite a statute that no longer contains the provisions they rely on. The obligations did not disappear — they moved, and in places they changed shape.
Two are new in substance rather than in numbering: the duty to establish and implement a documented privacy management programme, and a Privacy Impact Assessment threshold that is considerably narrower than most summaries describe.
Who counts as a public body
ATIA s.1(m) defines a local government body, and the list is wider than most people expect: municipalities, improvement districts, special areas, regional services commissions, irrigation and drainage district boards, management bodies under the Alberta Housing Act, Metis settlements and the Metis Settlements General Council, police commissions and services, municipal and intermunicipal library boards, and any board, committee, commission, panel, agency or corporation created or owned by one of those.
That matters because shared delivery with a library board, a housing management body or a regional services commission is not a vendor relationship — it is two public bodies running a common programme, which changes the analysis entirely.
When an assessment is actually required.
POPA does not require a PIA for every system that touches personal information. Section 7(1) sets a threshold with two limbs — and a practice has to clear the preconditions before either limb is reached at all.
The preconditions: the practice, programme, project or service must be new, or a substantial change to an existing one, and it must involve the collection, use or disclosure of personal information. A system that has run unchanged for six years is not caught by s.7(1) merely because it holds personal information.
- s.7(1)(a)Loss of, unauthorized access to, or unauthorized disclosure of the personal information could result in significant harm, as determined under s.4.
- s.7(1)(b)One or more of the factors requiring submission under s.7(5) applies.
The asymmetry between them is the part worth understanding. Limb (a) stands on its own: a practice can require a completed assessment on significant-harm grounds with no obligation to file it. Anything caught by limb (b) must be both completed and submitted.
The six factors under s.7(5)
- 7(5)(a)Personal information deemed to be of high sensitivity
- 7(5)(b)Personal information of a significant percentage of the population served
- 7(5)(c)Data matching between two or more public bodies
- 7(5)(d)Part of a common or integrated programme or service
- 7(5)(e)Development or use of innovative technology
- 7(5)(f)The Commissioner requests a copy under POPA s.27(1)(j)
"High sensitivity" in (a) is a defined term, not a judgement call. Section 1 deems only three things to be of high sensitivity: biometric information, financial information, and personal information respecting a minor, senior or vulnerable individual. It is a closed list.
Three provisions that reduce the work
s.7(3) — detail must be commensurate with the complexity of the practice. For a village of two hundred people that is a statutory limit on scope, not a courtesy.
s.7(4)(a) — where a practice already has a PIA, a substantial change can be handled by amending it rather than starting again.
s.7(4)(b) — for a common or integrated programme, or data matching between two or more public bodies, those bodies may prepare one joint PIA, each adding an addendum for its own circumstances. This sits in the Regulation itself, not in guidance, and it is the single most useful provision available to small municipalities sharing a service.
What an assessment must contain — s.7(2)
- (a)A summary of the purpose of the collection, use or disclosure
- (b)The types of personal information involved, and the reasonable security arrangements protecting it
- (c)The legal authority for the collection, use or disclosure
- (d)Privacy risks identified, and the strategies mitigating them
- (e)Administrative, physical and technical safeguards
- (f)Procedures for accuracy, correction and retention
- (g)A governance structure where two or more bodies share a programme
Seven, not six — and (b) is the one most often dropped. Under s.7(6), where submission is required and an agreement underlies the practice, the privacy-related portions of that agreement must be submitted alongside.
Test a practice against s.7(1).
This applies the statutory test and nothing else — the same sequence I work through system by system in a screening engagement. It answers two separate questions: whether an assessment is required, and whether it must be submitted.
Seven things in circulation that are wrong.
These come from summaries, vendor material and secondhand briefing notes, and several are in wide use. Every correction can be checked against the section cited in a couple of minutes — the sources are linked at the foot of this page.
A PIA is required for any system that handles personal information.
Only for a practice that is new or substantially changed, involves personal information, and then meets limb (a) or limb (b). Long-standing systems running unchanged sit outside s.7(1) entirely.AR 143/2025 s.7(1)
Section 7(1) sets out six triggers for a PIA.
Section 7(1) has two limbs. Five of the six factors live in s.7(5), which governs submission to the Commissioner — a different obligation from preparation.AR 143/2025 s.7(1), s.7(5)
There are five factors requiring submission.
Six. High sensitivity, a significant percentage of the population served, data matching between public bodies, a common or integrated programme, innovative technology, and a request from the Commissioner.AR 143/2025 s.7(5)(a)–(f)
Health and medical information is high sensitivity.
Section 1 defines high sensitivity as a closed list: biometric information, financial information, and information respecting a minor, senior or vulnerable individual. Health information usually qualifies through the third — and an assessment should say so rather than assert sensitivity.AR 143/2025 s.1
Section 7(2) sets six content requirements.
Seven, (a) through (g). The one most often omitted is (b) — the types of personal information involved together with the reasonable security arrangements protecting it.AR 143/2025 s.7(2)
Joint PIAs are a Government of Alberta recommendation.
They are in the Regulation. Section 7(4)(b) permits a joint assessment for a common or integrated programme or for data matching, with each participating body preparing an addendum. That is an entitlement, not guidance.AR 143/2025 s.7(4)(b)
Metis settlements are not public bodies under the legislation.
ATIA s.1(m) expressly lists Metis settlements and the Metis Settlements General Council among local government bodies. First Nations are not listed and are not public bodies under the Act — that distinction is real, but it applies only to First Nations.ATIA, SA 2024 c A-1.4, s.1(m)
Four pieces of work, each with a defined output.
I take them on singly. Nothing here depends on buying the rest.
Privacy Management Program — review, or built from scratch
Where a programme exists: a written review against the five matters s.6(1) requires, the additional requirements s.6(2) imposes where volume or sensitivity is high — including for automated and AI-assisted systems — and the publication duty under s.6(3). Programmes written in-house are the common case, and the hardest thing to check from inside the office that wrote them. Output is a marked-up review with each gap identified by section and the wording needed to close it.
Where none exists: the programme itself — policies, procedures, roles, an information inventory, staff training, breach response, and a version fit to publish under s.6(3). The 11 June 2026 deadline has passed, so this is now a remediation job rather than a preparation one, and it is the work most small municipalities still have outstanding.
PIA screening across a municipality's systems
A system-by-system determination of what s.7(1) actually catches and what it does not, and for anything caught, whether s.7(5) makes submission mandatory. Output is a written screening record — the document to point at when someone asks why no assessment was prepared for a given system.
Joint Privacy Impact Assessment
For a shared service, commission or mutual-aid arrangement: one assessment on the Commissioner's template covering the common programme, with a short addendum for each participating body. Costs are split across the bodies rather than carried by each. This is the only structure in which a full assessment is economically sensible for municipalities under a thousand people.
Single-body Privacy Impact Assessment
A complete assessment against the OIPC POPA PIA Template, Sections A through H with appendices, meeting all seven content requirements in s.7(2) and, where submission is required, assembled with the privacy-related portions of any underlying agreement as s.7(6) requires.
Flat, and published.
Quoted before anything starts, and set out here so a CAO can work out the cost of a decision without having to ask for a proposal first. Almost nobody in this market publishes rates; there is no good reason for that. The estimator below prices a specific engagement.
| Work | Fee (CAD) |
|---|---|
| Privacy Management Program — review of an existing programme, one public body | $2,500 |
| Each additional body sharing the same administration | $900 |
| Privacy Management Program — built from scratch, POPA s.25 and s.6 | from $6,500 |
| Each additional body sharing the same administration | $1,500 |
| PIA screening across a municipality's systems | $1,900 |
| Joint Privacy Impact Assessment under s.7(4)(b) — shared assessment | from $4,900 |
| Addendum for each participating body | $750 |
| Single-body Privacy Impact Assessment, OIPC template A–H | from $5,200 |
| Ongoing privacy support — s.25(3) requests, breach questions, annual review | $350 / month |
| Work outside these scopes, hourly | $165 |
Below the $75,000 New West Partnership threshold, so a municipality may direct-award without a public tender.
How I work.
This is an independent practice. I am not a law firm and I do not act through one.
Everything I produce is worked from the primary sources — the Protection of Privacy Act, the Access to Information Act, the Regulation and the Commissioner's own template — rather than from fact sheets or secondhand summaries. §04 is what that difference looks like. Each of those seven statements is in circulation, and each is wrong in a way a reader working from the Regulation would catch.
The work is aimed at the municipalities least able to absorb it internally: villages, summer villages, small towns, and the shared-administration offices carrying five or seven public bodies between them. Those offices have the same statutory obligations as Calgary and a fraction of the capacity — and the Regulation, in s.7(3) and s.7(4)(b) and in the proportionality requirement at POPA s.25(2)(a), is considerably more accommodating of that than they are usually told.
I am happy to be checked. Every claim here carries the section it rests on.
Read them yourself.
Want a read on where your municipality actually stands?
Say so and I'll give you one. An eight-page note setting out the thresholds, the programme requirements and the seven content requirements in full is available on request, at no cost.
- Practice
- Arya Privacy
- Name
- Aditya Arya
- Telephone
- 825-965-6690
- Region
- Alberta · MST