
FOIP Compliance for Alberta Public Bodies: Access, Privacy and Security
Alberta has split access and privacy into two separate Acts. What that means for public bodies, and the security duties that carried across unchanged.
GuardsArm Team
Security Experts

Alberta public bodies spent decades under a single statute covering both access to information and protection of privacy. The province has since separated those two functions into distinct legislation, on the reasoning that they are different disciplines that had been awkwardly sharing one Act.
For a public body the practical consequence is administrative rather than philosophical: two regimes to track, two sets of obligations to assign, and a transition to manage. Confirm which Act currently governs each of your obligations and on what timeline — the split has moved things around, and policy documents written against the old single-statute structure will point at the wrong provisions.
What has not changed is the substance of what a public body must actually do.
The access side
Anyone may request records held by a public body. The obligations that generate complaints are consistently the same three:
| Obligation | Where it goes wrong |
|---|---|
| Respond within the statutory timeline | Requests sit with a programme area with no tracking |
| Conduct an adequate search | Only the obvious repository is searched |
| Apply exceptions correctly, and only as far as needed | Over-redaction, or whole-record withholding where severing would do |
Adequate search is the one with a security dimension. A public body cannot search what it cannot find. Records in a departed employee's mailbox, on an unmanaged share, or in a system nobody inventoried are still records subject to the request. A defensible search rests on knowing where information lives, which is the same asset and data inventory your security programme needs.
The privacy side
Collection must be authorised, limited, and — as a default — made directly from the individual, with notice of the purpose and authority. Use and disclosure are restricted to the purpose of collection, a consistent purpose, or a specific statutory permission.
Two recurring failures:
- Indirect collection by habit. Pulling information from another programme area or another body because it is easier than asking the individual, without a provision that authorises it.
- Consistent purpose stretched past breaking. A purpose is consistent if it has a direct and reasonable connection to the original one. Analytics, research and service improvement are frequently asserted to be consistent when they are a new purpose needing its own authority.
The security duty
A public body must protect personal information with reasonable security arrangements against risks including unauthorised access, collection, use, disclosure and destruction.
"Reasonable" is judged after an incident, against what a comparable body would have done. In practice an investigation will ask for:
Note the last item. Unauthorised destruction is a privacy breach, which puts ransomware and backup integrity squarely inside your privacy obligations rather than beside them. See immutable backups.
Where public bodies most often lose points
- No record of the search. The search was adequate but nothing documents it.
- Access reviews that never happen. Staff accumulate access as they move roles.
- Retention by inertia. Records kept indefinitely because deleting requires a decision.
- Shadow systems. A programme area's spreadsheet or SaaS tool, outside every inventory.
- Contractors treated as outside the perimeter when they hold personal information on your behalf.
Cloud services and the custody question
Public bodies adopting SaaS run into a question private organisations largely avoid: personal information in the custody or under the control of a public body remains subject to the Act wherever it physically sits. Control does not transfer with hosting.
Before a programme area signs anything:
- Where will the information reside, including backups, replicas and support access from other jurisdictions
- Can you meet an access request against it — can you extract records in a reviewable form within the statutory timeline
- Can you meet a retention and disposal schedule, including verified deletion
- What are the vendor's breach notification terms, and do they give you enough time to meet your own obligation
- Who at the vendor can read the data, and is that access logged
The last two are the ones standard vendor paper handles badly. A contract promising notification "without undue delay" does not help a public body working to a fixed statutory clock.
Where to start
Inventory where personal information actually lives, including the systems no one approved. It is the foundation of a defensible search, of retention, and of the security duty — three obligations served by one piece of work.
GuardsArm supports Alberta public bodies with privacy and security assessments. See Alberta FOIP compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


