Back to Blog
Compliance
4 min read

FOIP Compliance for Alberta Public Bodies: Access, Privacy and Security

Alberta has split access and privacy into two separate Acts. What that means for public bodies, and the security duties that carried across unchanged.

GuardsArm Team

Security Experts

September 25, 2026

FOIP compliance for Alberta public bodies

Alberta public bodies spent decades under a single statute covering both access to information and protection of privacy. The province has since separated those two functions into distinct legislation, on the reasoning that they are different disciplines that had been awkwardly sharing one Act.

For a public body the practical consequence is administrative rather than philosophical: two regimes to track, two sets of obligations to assign, and a transition to manage. Confirm which Act currently governs each of your obligations and on what timeline — the split has moved things around, and policy documents written against the old single-statute structure will point at the wrong provisions.

What has not changed is the substance of what a public body must actually do.

Two Acts now, not one
Access and privacy separated; check which governs each duty
Search must be adequate
You cannot search what you never inventoried
Destruction is a breach
Ransomware sits inside your privacy duty, not beside it

The access side

Anyone may request records held by a public body. The obligations that generate complaints are consistently the same three:

ObligationWhere it goes wrong
Respond within the statutory timelineRequests sit with a programme area with no tracking
Conduct an adequate searchOnly the obvious repository is searched
Apply exceptions correctly, and only as far as neededOver-redaction, or whole-record withholding where severing would do

Adequate search is the one with a security dimension. A public body cannot search what it cannot find. Records in a departed employee's mailbox, on an unmanaged share, or in a system nobody inventoried are still records subject to the request. A defensible search rests on knowing where information lives, which is the same asset and data inventory your security programme needs.


The privacy side

Collection must be authorised, limited, and — as a default — made directly from the individual, with notice of the purpose and authority. Use and disclosure are restricted to the purpose of collection, a consistent purpose, or a specific statutory permission.

Indirect collection needs authority, not convenience
Collecting personal information from another programme area rather than the individual is lawful only where a provision permits it. Doing it because it is faster is the single most common privacy finding against public bodies.

Two recurring failures:

  • Indirect collection by habit. Pulling information from another programme area or another body because it is easier than asking the individual, without a provision that authorises it.
  • Consistent purpose stretched past breaking. A purpose is consistent if it has a direct and reasonable connection to the original one. Analytics, research and service improvement are frequently asserted to be consistent when they are a new purpose needing its own authority.

The security duty

A public body must protect personal information with reasonable security arrangements against risks including unauthorised access, collection, use, disclosure and destruction.

"Reasonable" is judged after an incident, against what a comparable body would have done. In practice an investigation will ask for:

What "reasonable security arrangements" is read to meanAccess control and review, encryption on mobile devices, logging adequate to reconstruct access, retention and disposal, and protection against unauthorised destruction.Access control and reviewWho can reach personal information, checked periodicallyEncryption on mobile devices and mediaThe classic lost-laptop findingLogging sufficient to reconstruct accessNeeded to answer what was exposedRetention and secure disposalHolding records past their schedule is its own exposureProtection against unauthorised destructionBackup integrity is a privacy control here
Judged after the fact against what a comparable public body would have done.

Note the last item. Unauthorised destruction is a privacy breach, which puts ransomware and backup integrity squarely inside your privacy obligations rather than beside them. See immutable backups.


Where public bodies most often lose points

  1. No record of the search. The search was adequate but nothing documents it.
  2. Access reviews that never happen. Staff accumulate access as they move roles.
  3. Retention by inertia. Records kept indefinitely because deleting requires a decision.
  4. Shadow systems. A programme area's spreadsheet or SaaS tool, outside every inventory.
  5. Contractors treated as outside the perimeter when they hold personal information on your behalf.

Cloud services and the custody question

Public bodies adopting SaaS run into a question private organisations largely avoid: personal information in the custody or under the control of a public body remains subject to the Act wherever it physically sits. Control does not transfer with hosting.

Before a programme area signs anything:

  • Where will the information reside, including backups, replicas and support access from other jurisdictions
  • Can you meet an access request against it — can you extract records in a reviewable form within the statutory timeline
  • Can you meet a retention and disposal schedule, including verified deletion
  • What are the vendor's breach notification terms, and do they give you enough time to meet your own obligation
  • Who at the vendor can read the data, and is that access logged

The last two are the ones standard vendor paper handles badly. A contract promising notification "without undue delay" does not help a public body working to a fixed statutory clock.


Where to start

Inventory where personal information actually lives, including the systems no one approved. It is the foundation of a defensible search, of retention, and of the security duty — three obligations served by one piece of work.

GuardsArm supports Alberta public bodies with privacy and security assessments. See Alberta FOIP compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.