Treadstone Associates
Article · 8 min read

Alberta and BC privacy rules for AI

A business operating in Alberta or British Columbia is very often not actually a PIPEDA business for its everyday, intra-provincial dealings. Both provinces run their own private-sector privacy statute, both are named Personal Information Protection Act, and both apply to an AI tool the same way they apply to any other system that touches personal information.

Treadstone Associates · Updated 2026

Key takeaways

  • • Alberta and BC each have their own Personal Information Protection Act, both recognized as “substantially similar” to PIPEDA, so PIPEDA generally steps aside for information handled inside that province.
  • • The federal government’s power to grant that exemption is written into PIPEDA itself, at paragraph 26(2)(b).
  • • PIPEDA still applies in both provinces to cross-border data transfers and to federally regulated businesses such as banks and telecoms.
  • • Alberta’s privacy regulator has published AI-specific guidance items; BC’s has not published a dedicated AI guidance page from the same starting point, but its Personal Information Protection Act still governs an AI tool’s use of personal information in the ordinary way.

Two provinces, two statutes, one federal carve-out

The Office of the Privacy Commissioner of Canada states the position without qualification: “Alberta, British Columbia (B.C.) and Quebec have their own private-sector privacy laws that have been deemed substantially similar to PIPEDA”, naming “Alberta: Personal Information Protection Act overseen by the Office of the Information and Privacy Commissioner of Alberta” and “B.C.: Personal Information Protection Act overseen by the Office of the Information and Privacy Commissioner for British Columbia”, adding that organizations subject to these laws “are generally exempt from PIPEDA with respect to the collection, use or disclosure of personal information that occurs within that province.” (OPC, provincial laws that may apply instead of PIPEDA) The federal statute itself grants that room deliberately: the Governor in Council may, by order, “if satisfied that legislation of a province that is substantially similar to this Part applies to an organization, a class of organizations, an activity or a class of activities, exempt the organization, activity or class from the application of this Part.” (PIPEDA, s.26(2)(b)) An Alberta or BC business handling an AI vendor question is therefore usually asking a provincial-statute question, not a federal one — even though the underlying obligations (consent, safeguards, access) read very similarly across all three regimes.

Where PIPEDA still reaches in, regardless of province

The exemption is not total. The OPC is explicit that “even in those provinces, PIPEDA still applies to: transactions involving personal information transferred across borders” and to “federal works, undertakings or businesses” (FWUBs) — “such as banks, telecommunications and transportation companies.” (OPC, provincial laws that may apply instead of PIPEDA) An Alberta business sending customer data to a US-hosted AI vendor is engaging PIPEDA’s cross-border rules for that specific transfer — covered in our companion piece on cross-border data transfers — on top of, not instead of, its obligations under Alberta’s own Act for the rest of its handling of that information.

Alberta’s regulator has moved specifically on AI

The Office of the Information and Privacy Commissioner of Alberta maintains a dedicated AI resource page, listing items including a “Privacy Impact Assessment (PIA) Template and Completion Guide (POPA)”, a “Joint Statement: AI-Generated Imagery and the Protection of Privacy (2026)”, “AI Scribe PIA Guidance”, and “Guidance for Small Custodians on the use of Artificial Intelligence.” (OIPC Alberta, AI resources) The privacy impact assessment is the operative mechanism here: Alberta’s Personal Information Protection Act framework expects an organization to work through the privacy implications of a new system, including an AI tool, before it goes live, and the regulator has built AI-specific templates for exactly that exercise rather than leaving businesses to adapt a generic one.

Alberta also carries its own breach-notification duty, with its own penalty

Alberta’s Act adds an obligation neither PIPEDA nor BC’s statute mirrors in quite the same form: section 34.1 requires an organization, without unreasonable delay, to notify the Commissioner of any incident involving the loss of or unauthorized access to or disclosure of personal information, wherever a reasonable person would consider there exists “a real risk of significant harm to an individual”. (Personal Information Protection Act, s.34.1) If an AI vendor processing an Alberta business’s customer records is itself breached, that notification duty runs to the Alberta business, not the vendor — and failing to give it is a listed offence, carrying a fine on conviction of up to $10,000 for an individual and up to $100,000 for an organization. (PIPA, s.59(1)(e.1) and s.59(2))

BC’s regulator is reachable, but check what it has actually published before citing it

The Office of the Information and Privacy Commissioner for British Columbia is live and publishes guidance documents, investigation and audit reports, and orders under BC’s own Act. (OIPC British Columbia) It has not published an AI-specific guidance page structured the same way as Alberta’s at the time of writing, so a BC business should not assume Alberta’s AI resource list applies across the border — the underlying BC Personal Information Protection Act still governs, but AI-specific regulator guidance in BC should be checked directly rather than borrowed from a neighbouring province.

A worked example

A Calgary accounting firm, operating only within Alberta, wants to deploy an AI tool to draft client engagement letters from intake-form answers. Because the firm’s activity is entirely intra-provincial, Alberta’s Personal Information Protection Act — not PIPEDA — is the operative statute, and OIPC Alberta’s privacy-impact-assessment materials are the right starting template for evaluating the tool before rollout. If the same firm opens a Vancouver office and the AI vendor’s servers are outside Canada, two more layers activate at once: BC’s own Act for the Vancouver office’s intra-provincial handling, and PIPEDA’s cross-border rules for the transfer to the foreign-hosted vendor, which the provincial exemption does not touch.

Related: whether PIPEDA applies when a business uses AI, what applies when an AI tool processes data outside Canada, and Quebec’s separate Law 25 automated-decision rule.

Common questions

Is Alberta’s Personal Information Protection Act materially different from PIPEDA for AI purposes?

The OPC describes it as “substantially similar” in overall protection, which is the statutory test for the federal exemption — but it is a distinct statute with its own regulator, its own text, and its own guidance, so an Alberta business should work from OIPC Alberta’s own materials rather than assume PIPEDA case law transfers over unchanged.

Does a BC or Alberta business get to ignore PIPEDA entirely once it uses an AI vendor?

No — the provincial exemption covers collection, use and disclosure occurring within that province. The moment personal information crosses a border, such as to a foreign-hosted AI vendor, PIPEDA’s own cross-border rules apply on top of the provincial statute.

Are Quebec, Alberta and BC treated the same way under PIPEDA?

They share the same statutory mechanism — a substantially similar provincial law recognized under s.26(2)(b) — but Quebec’s Law 25 also contains an automated-decision-specific provision that Alberta and BC’s statutes do not carry in the same form, which is why Quebec gets its own dedicated treatment elsewhere in this hub rather than being folded into this one.

A bank branch in Calgary uses an AI tool on customer files — PIPEDA or Alberta’s Act?

PIPEDA, because banks are a named example of a “federal work, undertaking or business” under s.4(1)(b), and the provincial exemption does not reach federally regulated businesses even for activity that happens entirely inside Alberta — the same carve-out the OPC names for telecommunications and transportation companies.

A provincial statute changes who signs off on a rollout, not just who is cited

Operations covers building a privacy-impact review into an AI deployment from the start.